CVE-2026-91963
Received Received - Intake

Heap Memory Disclosure in FreeRDP

Vulnerability report for CVE-2026-91963, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: VulnCheck

Description

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
freerdp freerdp to 3.31.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-457 The code uses a variable that has not been initialized, leading to unpredictable or unintended results.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

FreeRDP versions before 3.31.0 have a flaw in the USB redirection channel where a malicious RDP server can cause failing USB transfers. This allows reading uninitialized heap memory from the client, which can bypass ASLR and potentially enable remote code execution when combined with other memory corruption issues.

Detection Guidance

Detection requires monitoring for unusual USB redirection activity or failed USB transfer attempts in FreeRDP clients. Check FreeRDP version with 'xfreerdp --version' or 'freerdp2 --version'. Inspect logs for USB redirection errors or unexpected memory access patterns.

Impact Analysis

If you use FreeRDP versions before 3.31.0, an attacker controlling the RDP server could exploit this to read sensitive memory from your system. This could lead to information disclosure or be used as a stepping stone for further attacks like remote code execution.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating confidentiality requirements in GDPR and HIPAA. Organizations using vulnerable FreeRDP versions may face compliance risks due to potential data breaches or unauthorized information disclosure.

Mitigation Strategies

Upgrade FreeRDP to version 3.31.0 or later immediately. Disable USB redirection in RDP clients if not required. Monitor network traffic for suspicious RDP server behavior targeting USB channels.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91963. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart