FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a malicious RDP server can crash the FreeRDP client by sending audio data in IMA ADPCM format with an invalid initial step index value (>= 89). The unvalidated step index is read directly from the network and used to index into a 89-entry lookup table, triggering a WINPR_ASSERT() failure and process abort via SIGABRT. This affects any FreeRDP client that has audio redirection (RDPSND) enabled, which is the default configuration. This issue has been patched in version 3.24.2.
CVSS Details
- CVSS 4.0 Base Score: 6.9 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 6.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade freerdp | Apr 1, 2026 | Mar 30, 2026 |
| Amazon Linux Ami 2 | — | Upgrade libwinpr-develUpgrade freerdpUpgrade freerdp-debuginfoUpgrade freerdp-develUpgrade libwinprUpgrade freerdp-libs | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade freerdp-serverUpgrade freerdpUpgrade libwinpr-debuginfoUpgrade libwinpr-develUpgrade freerdp-debugsourceUpgrade freerdp-libsUpgrade freerdp-libs-debuginfoUpgrade freerdp-debuginfoUpgrade libwinprUpgrade freerdp-server-debuginfoUpgrade freerdp-devel | Apr 14, 2026 | Mar 30, 2026 |
| Debian | — | Upgrade freerdp3 | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Mar 30, 2026 |
| Ubuntu | — | Upgrade libfreerdp3-3Upgrade freerdp-x11Upgrade freerdp3-x11 | Jul 21, 2026 | Jul 20, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub