CVE-2026-91951
Analyzed Analyzed - Analysis Complete

Out-of-Bounds Write in FreeRDP USB Redirection

Vulnerability report for CVE-2026-91951, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-24

Assigner: VulnCheck

Description

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, causing denial of service when verbose asserts are enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-24
Generated
2026-10-06
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
freerdp freerdp From 3.14.0 (inc) to 3.31.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds write flaw in FreeRDP versions before 3.31.0. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past a 16-byte buffer in the urbdrc client channel's urb_send_current_frame_number_result() function. This causes denial of service when verbose asserts are enabled.

Detection Guidance

Detecting this vulnerability requires checking FreeRDP versions and monitoring for suspicious USB redirection activity. Use 'xfreerdp --version' or 'freerdp2 --version' to verify if your FreeRDP version is below 3.31.0. Inspect RDP server logs for unusual USB redirection messages or crashes during client connections.

Impact Analysis

If you use FreeRDP versions 3.14.0 through 3.30.0 with USB redirection enabled, a malicious RDP server could crash your client or corrupt memory. The attack requires a redirected USB device to be present but does not depend on the actual device type.

Compliance Impact

This vulnerability primarily causes denial of service or memory corruption in FreeRDP clients when a malicious RDP server sends a crafted message. It does not directly impact data confidentiality or integrity, which are key concerns for GDPR and HIPAA. However, if the denial of service disrupts critical systems handling protected health or personal data, it could indirectly affect compliance by impairing access to necessary systems.

Mitigation Strategies

Immediately upgrade FreeRDP to version 3.31.0 or later. Disable USB redirection in RDP client configurations if not required. Monitor network traffic for malicious USB redirection attempts and apply patches to all affected systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91951. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart