{"id":"CVE-2026-63117","title":"FreeRDP is a free implementation of the Remote Desktop Protocol","summary":"FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlign equal to 8 and nChannels equal to 2 to make the `bs` calculation in rdpsnd_server_sele…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-369"],"published":"2026-08-19","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:19:49.197","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-63117","references":[{"url":"https://github.com/FreeRDP/FreeRDP/commit/b78fc0b138fe8f08a8b102e193ffb32986f4449a","label":"security-advisories@github.com"},{"url":"https://github.com/FreeRDP/FreeRDP/pull/12980","label":"security-advisories@github.com"},{"url":"https://github.com/FreeRDP/FreeRDP/releases/tag/3.28.0","label":"security-advisories@github.com"},{"url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v64m-xxfw-hrv6","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00389,"epssPercentile":0.32778,"ingestedAt":"2026-09-09T21:22:45.541Z","slug":"CVE-2026-63117","body":"## Overview\n\nFreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlign equal to 8 and nChannels equal to 2 to make the `bs` calculation in rdpsnd_server_select_format in channels/rdpsnd/server/rdpsnd_main.c equal zero. The subsequent out_frames modulo `bs` operation raises SIGFPE and terminates the server-side rdpsnd channel process. This vulnerability fixed in 3.28.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}