Integer overflow in FreeRDP - #VU138643
Published: July 20, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to integer overflow in the Audio Input Redirection virtual channel WinMM backend when processing a crafted FramesPerPacket value in RDP audio input negotiation messages. A remote attacker can send a specially crafted RDP server message to cause a denial of service.
User interaction is required to connect to a malicious or compromised RDP server with audio input redirection enabled.