CVE-2026-91963

Summary

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.

Affected Software

VendorProductVersion RangeStatus
FreeRDPFreeRDP2.0.0 < 3.0.0affected
FreeRDPFreeRDP3.0.0 < 3.31.0affected
FreeRDPFreeRDP3.31.0unaffected
FreeRDPFreeRDP0 < 3.31.0affected
FreeRDPFreeRDP3.31.0unaffected

Weaknesses

  • CWE-457: Use of Uninitialized Variable

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: no
    • Technical Impact: partial

Additional References

References