Remote Desktop Protocol Vulnerability in FreeRDP Software
CVE-2026-63633

7.7HIGH

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-63633?

FreeRDP, a free implementation of the Remote Desktop Protocol, has a vulnerability in the handling of audio decoding. Specifically, the function freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c does not ensure sufficient buffer capacity when processing incoming audio streams. A malicious RDP server can exploit this vulnerability by negotiating an audio format that leads to excessive data being written beyond the allocated buffer, resulting in heap corruption. This issue can cause crashes and potentially allow unauthorized code execution within the client context. Users should update to version 3.28.0 or later to mitigate this risk.

Affected Version(s)

FreeRDP < 3.28.0

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.