Description
FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend. A malicious RDP server can send a control-transfer request with OutputBufferSize set to 65536, triggering a reachable assertion that terminates the client process.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

FreeRDP implements the URBDRC control-transfer protocol. In versions before 3.31.0 the client fails to validate the OutputBufferSize value before forwarding the data to the libusb backend. When a malicious RDP server sends a control-transfer request with OutputBufferSize set to 65536, the client triggers a reachable assertion that terminates the process. The flaw does not allow data disclosure or code execution; it can be used repeatedly to bring the client down, effectively denying service.

Affected Systems

All systems that run the FreeRDP client before release 3.31.0 are affected. This includes any desktop or server environment using the FreeRDP binaries or libraries when connecting to RDP servers, regardless of operating system.

Risk and Exploitability

The CVSS score of 7.1 classifies this vulnerability as moderately severe. The EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation. The attack requires an attacker to control the RDP server that the victim connects to; because it is not listed in CISA’s KEV catalog, no widespread exploits are currently documented.

Generated by OpenCVE AI on September 20, 2026 at 16:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the FreeRDP client to version 3.31.0 or later, which includes proper validation of OutputBufferSize.
  • If an upgrade is not immediately possible, disable the URBDRC control‑transfer feature in the FreeRDP configuration to prevent the vulnerable code path.
  • Restrict inbound connections from untrusted RDP servers using firewall rules or client‑side filtering to reduce the attack surface.

Generated by OpenCVE AI on September 20, 2026 at 16:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails to validate OutputBufferSize before forwarding to the libusb backend. A malicious RDP server can send a control-transfer request with OutputBufferSize set to 65536, triggering a reachable assertion that terminates the client process.
Title FreeRDP before 3.31.0 Denial of Service via URBDRC
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-617
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T17:23:04.862Z

Reserved: 2026-09-15T11:08:44.670Z

Link: CVE-2026-91961

cve-icon Vulnrichment

Updated: 2026-09-18T17:16:49.707Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:51.613

Modified: 2026-09-23T20:02:24.160

Link: CVE-2026-91961

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T15:18:15Z

Links: CVE-2026-91961 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses