Description
FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECT_CONFIGURATION message with permuted InterfaceNumber values to read past allocated heap memory and crash the client.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Memory Disclosure / Crash
Action: Patch Immediately
AI Analysis

Impact

The flaw is an out-of-bounds read in FreeRDP’s URBDRC channel within the func_get_ep_desc function. The code incorrectly indexes interface arrays by position instead of the protocol field InterfaceNumber, allowing an attacker-controlled RDP server to trigger a read past allocated heap memory. Based on the description, it is inferred that the server sends a crafted SELECT_CONFIGURATION message with permuted InterfaceNumber values to abuse this logic, potentially exposing sensitive memory contents or causing the client to crash.

Affected Systems

All FreeRDP releases before version 3.31.0 are impacted. The vulnerability resides in the URBDRC channel implementation and is present in all builds that compile the default FreeRDP client.

Risk and Exploitability

The CVSS base score of 7.1 indicates a high-severity issue. The EPSS score is reported as < 1%, suggesting a low likelihood of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker-controlled RDP server to initiate a connection to the vulnerable client and send a specifically crafted SELECT_CONFIGURATION request. Once processed, the client performs an out-of-bounds read that can expose sensitive memory contents or cause the client to terminate, but no active exploit has been publicly documented to date.

Generated by OpenCVE AI on September 20, 2026 at 16:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to FreeRDP 3.31.0 or later to obtain the fixed URBDRC implementation.
  • Restrict incoming RDP traffic to the client using firewall rules, allowing only trusted sources or devices that connect through a VPN tunnel.
  • Implement network segmentation or additional monitoring to detect and limit exposure of the RDP service to authorized users only.

Generated by OpenCVE AI on September 20, 2026 at 16:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function that indexes interface arrays by position instead of protocol field InterfaceNumber. A malicious RDP server can send a crafted SELECT_CONFIGURATION message with permuted InterfaceNumber values to read past allocated heap memory and crash the client.
Title FreeRDP before 3.31.0 Out-of-Bounds Read via URBDRC
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-125
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T17:23:05.099Z

Reserved: 2026-09-15T11:07:34.398Z

Link: CVE-2026-91956

cve-icon Vulnrichment

Updated: 2026-09-18T17:16:51.807Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:50.500

Modified: 2026-09-24T12:16:54.063

Link: CVE-2026-91956

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:18:11Z

Links: CVE-2026-91956 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses