Remote Desktop Protocol Vulnerability in FreeRDP Software
CVE-2026-63633
7.7HIGH
What is CVE-2026-63633?
FreeRDP, a free implementation of the Remote Desktop Protocol, has a vulnerability in the handling of audio decoding. Specifically, the function freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c does not ensure sufficient buffer capacity when processing incoming audio streams. A malicious RDP server can exploit this vulnerability by negotiating an audio format that leads to excessive data being written beyond the allocated buffer, resulting in heap corruption. This issue can cause crashes and potentially allow unauthorized code execution within the client context. Users should update to version 3.28.0 or later to mitigate this risk.
Affected Version(s)
FreeRDP < 3.28.0
