Description
FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.
Published: 2026-09-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote code execution potential via memory disclosure
Action: Patch Now
AI Analysis

Impact

FreeRDP versions before 3.31.0 expose uninitialized heap memory through the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers that cause the client to read uninitialized memory, defeating address space layout randomization. When this information disclosure is chained with other memory corruption bugs, it can lead to remote code execution on the client machine.

Affected Systems

The affected product is the FreeRDP client. All releases from version 2.0.0 up to and including 3.30.0 are vulnerable.

Risk and Exploitability

The vulnerability has a CVSS score of 7.1, indicating high severity, and an EPSS score of < 1%; it is not listed in KEV. The attack requires a malicious RDP server that triggers USB transfer failures. The lack of a direct patch or workaround, aside from disabling USB redirection, means the risk remains significant if other exploitation vectors become available.

Generated by OpenCVE AI on September 20, 2026 at 16:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to FreeRDP 3.31.0 or later to eliminate the uninitialized memory flaw.
  • Disable USB redirection in the client configuration to avoid the vulnerable channel.
  • Restrict RDP connections to trusted servers, enforce TLS, and monitor for anomalous USB transfer activity to detect potential exploitation attempts.

Generated by OpenCVE AI on September 20, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-824
References
Metrics threat_severity

None

threat_severity

Important


Tue, 15 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.
Title FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc
First Time appeared Freerdp
Freerdp freerdp
Weaknesses CWE-457
CPEs cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Vendors & Products Freerdp
Freerdp freerdp
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-15T15:58:06.421Z

Reserved: 2026-09-15T11:08:44.670Z

Link: CVE-2026-91963

cve-icon Vulnrichment

Updated: 2026-09-15T15:57:47.331Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-15T16:17:51.907

Modified: 2026-09-23T20:08:36.160

Link: CVE-2026-91963

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T15:18:16Z

Links: CVE-2026-91963 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:30:18Z

Weaknesses
  • CWE-457

    Use of Uninitialized Variable

  • CWE-824

    Access of Uninitialized Pointer