PT-2026-66344 · Freerdp · Freerdp
CVE-2026-63652
·
Published
2026-07-02
·
Updated
2026-09-07
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.28.0
Description
In the
rdpsnd server recv formats function within channels/rdpsnd/server/rdpsnd main.c, the software frees context->client formats when receiving a malformed Client Audio Formats PDU without clearing the owning pointer or num client formats. An authenticated RDP client can trigger an error, such as a cbSize larger than the remaining record, leaving a dangling pointer in the server context. This leads to a double-free condition when rdpsnd server context free is called during session teardown, which can cause heap corruption and terminate the server.Recommendations
Update to version 3.28.0 or later.
Exploit
Fix
DoS
Double Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp