CVE-2026-91963 PUBLISHED

FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc

Assigner: VulnCheck
Reserved: 15.09.2026 Published: 15.09.2026 Updated: 15.09.2026

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor FreeRDP
Product FreeRDP
Versions Default: unaffected
  • affected from 2.0.0 to 3.0.0 (excl.)
  • affected from 3.0.0 to 3.31.0 (excl.)
  • Version 3.31.0 is unaffected
Vendor FreeRDP
Product FreeRDP
Versions Default: unaffected
  • affected from 0 to 3.31.0 (excl.)
  • Version 3.31.0 is unaffected

Credits

  • iarce-qb reporter

References

Problem Types

  • Use of Uninitialized Variable CWE