CVE-2026-91951
Received Received - Intake

Out-of-Bounds Write in FreeRDP USB Redirection

Vulnerability report for CVE-2026-91951, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: VulnCheck

Description

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, causing denial of service when verbose asserts are enabled.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
freerdp freerdp From 3.14.0 (inc) to 3.31.0 (exc)
freerdp freerdp to 3.31.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-617 The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds write flaw in FreeRDP versions before 3.31.0. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past a 16-byte buffer in the urbdrc client channel's urb_send_current_frame_number_result() function. This causes denial of service when verbose asserts are enabled.

Detection Guidance

Detecting this vulnerability requires checking FreeRDP versions and monitoring for suspicious USB redirection activity. Use 'xfreerdp --version' or 'freerdp2 --version' to verify if your FreeRDP version is below 3.31.0. Inspect RDP server logs for unusual USB redirection messages or crashes during client connections.

Impact Analysis

If you use FreeRDP versions 3.14.0 through 3.30.0 with USB redirection enabled, a malicious RDP server could crash your client or corrupt memory. The attack requires a redirected USB device to be present but does not depend on the actual device type.

Mitigation Strategies

Immediately upgrade FreeRDP to version 3.31.0 or later. Disable USB redirection in RDP client configurations if not required. Monitor network traffic for malicious USB redirection attempts and apply patches to all affected systems.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91951. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart