Description
FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.
Published: 2026-09-15
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Use-After-Free leading to potential arbitrary code execution
Action: Immediate Patch
AI Analysis

Impact

The FreeRDP server prior to version 3.31.0 contains a use‑after‑free flaw in its DRDYNVC parser. Authenticated clients can race AUDIN channel‑closure notifications against the parsing of DRDYNVC data so that the server dereferences a channel pointer after the associated synchronization lock has been released. This produces heap‑memory corruption that could allow an attacker to execute arbitrary code on the server.

Affected Systems

FreeRDP server (product name FreeRDP) running any version older than 3.31.0 is vulnerable. The issue is confined to the server side of the Remote Desktop Protocol implementation and only applies to installations that enable DRDYNVC channel support.

Risk and Exploitability

The vulnerability receives a CVSS score of 7.7, indicating high severity. An EPSS score below 1% indicates a low but non‑zero probability that the flaw will be exploited. It is not listed in the CISA KEV catalog. Exploitation requires an authenticated RDP session and careful timing of channel‑closure events, meaning the attacker must be able to interact with the server over RDP and trigger the race condition to corrupt heap memory.

Generated by OpenCVE AI on September 20, 2026 at 16:28 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to version 3.31.0 or later.
  • Disable the DRDYNVC channel in the server configuration to prevent the use‑after‑free condition.
  • Restrict RDP access to trusted users and firewall‑filter the RDP port so that only authenticated, authorized clients can connect.

Generated by OpenCVE AI on September 20, 2026 at 16:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a channel pointer after releasing the synchronization lock. Authenticated clients can race AUDIN channel closure messages against DRDYNVC data parsing to trigger heap-use-after-free when accessing freed channel objects.
Title FreeRDP Server before 3.31.0 Use-After-Free via DRDYNVC
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-362
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-16T15:41:11.938Z

Reserved: 2026-09-15T11:07:01.913Z

Link: CVE-2026-91947

cve-icon Vulnrichment

Updated: 2026-09-16T15:41:06.967Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:48.353

Modified: 2026-09-24T20:44:42.207

Link: CVE-2026-91947

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T15:18:05Z

Links: CVE-2026-91947 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses
  • CWE-362

    Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')

  • CWE-825

    Expired Pointer Dereference