Impact
FreeRDP before version 3.31.0 contains an integer overflow in its audin Apple backend when handling FramesPerPacket values supplied in MSG_SNDIN_OPEN messages. The overflow causes the AudioQueueAllocateBuffer size calculation to wrap, resulting in an undersized buffer allocation. This flaw exposes the application to potential out-of-bounds reads or writes (CWE‑131 and CWE‑787), which can lead to crashes or memory corruption in the process handling audio data.
Affected Systems
FreeRDP versions earlier than 3.31.0 that include the audin Apple backend are affected. The vulnerability is fixed in FreeRDP 3.31.0 and later. Users should verify that their FreeRDP installation does not enable the audin Apple backend if they cannot upgrade immediately.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote: an attacker who can act as an RDP server to a vulnerable FreeRDP client could send crafted MSG_SNDIN_OPEN messages. While no publicly disclosed exploitation code exists, the memory corruption introduced by an out-of-bounds access could be leveraged by a determined adversary to destabilize or compromise the target system if they control the audio payload.
OpenCVE Enrichment