CVE-2026-91955
Received Received - Intake

FreeRDP Remote Code Execution via Invalid Desktop Dimensions

Vulnerability report for CVE-2026-91955, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: VulnCheck

Description

FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, allowing remote attackers to crash the server. Attackers can send crafted RDP packets with zero or oversized dimensions to trigger division-by-zero or assertion failures in multifragment update capability calculations, terminating the server process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
freerdp freerdp to 3.31.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-369 The product divides a value by zero.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

FreeRDP before version 3.31.0 has a flaw where it does not properly check the DesktopWidth and DesktopHeight values provided by clients during GCC negotiation. Attackers can exploit this by sending specially crafted RDP packets with invalid dimensions like zero or excessively large values. This causes the server to crash due to division-by-zero errors or assertion failures when processing multifragment updates.

Detection Guidance

Detecting this vulnerability requires monitoring FreeRDP server instances for crashes or unusual behavior during RDP connection attempts. Check server logs for assertion failures or division-by-zero errors. Use network traffic analysis tools like Wireshark to inspect RDP packets for malformed DesktopWidth or DesktopHeight values in GCC negotiation packets.

Impact Analysis

If you are using a vulnerable version of FreeRDP, an attacker could remotely crash the FreeRDP server by sending malicious RDP packets. This could lead to denial-of-service conditions, disrupting services that rely on FreeRDP for remote desktop access.

Mitigation Strategies

Immediately upgrade FreeRDP to version 3.31.0 or later to address the vulnerability. If upgrading is not immediately possible, restrict network access to RDP services using firewalls or disable RDP until the update is applied. Monitor for suspicious connection attempts that may exploit this issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91955. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart