Impact
FreeRDP client versions <=3.28.0 contain a divide‑by‑zero flaw in the rdpecam camera redirection path. The vulnerability arises when the ecam_dev_process_start_streams_request() function parses the FrameRateDenominator field of a Server‑controlled StartStreamsRequest. Because the function does not validate this field, a zero value triggers a mathematical error during encoder initialization, causing the process to terminate. The flaw therefore results in a denial of service on the victim machine if an attacker gains the ability to send a crafted RDP packet. The flaw does not provide arbitrary code execution or network compromise beyond the client crash.
Affected Systems
All users running FreeRDP versions up to 3.28.0 with the camera redirection channel enabled are affected. The vulnerability is limited to the client side; the server side is not impacted. Clients running FreeRDP 3.29.0 or newer are not vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. No EPSS score is available, and the flaw is not listed in CISA’s KEV catalog, suggesting lower exploitation likelihood. The attack vector is remote: an attacker who can control an RDP session or compromise a server can send a malicious StartStreamsRequest to a client that has the channel enabled. The exploit requires no additional privileges on the client, and the attack can be repeated until the client terminates.
OpenCVE Enrichment