ZeroHour

CVE-2026-91963

large

Uninitialized Heap Memory Disclosure in FreeRDP USB Redirection Channel (pre-3.31.0)

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

FreeRDP versions before 3.31.0 disclose uninitialized heap memory via the urbdrc USB redirection channel (CWE-457). A malicious or compromised RDP server triggers failing USB transfer requests that cause the client to send back uninitialized heap contents. The leaked data can disclose heap addresses, defeating ASLR and enabling reliable remote code execution when chained with a memory corruption vulnerability. Any user of a FreeRDP-based client on a version before 3.31.0 who connects to an attacker-controlled server with USB redirection active is affected. No public proof-of-concept exists and the flaw is not listed in CISA's KEV catalog, so exploitation is not known to be occurring in the wild.

What to do: Upgrade FreeRDP to version 3.31.0 or later as soon as patched builds are available. If immediate upgrade is not possible, disable USB redirection entirely (do not enable the urbdrc channel, e.g., omit /usb options in xfreerdp) and restrict client connections to trusted, known RDP servers only. Administrators should also inventory downstream products that bundle FreeRDP (Linux distro packages, Remmina and similar clients, embedded appliance firmware) and apply vendor patches when released.

Affected
FreeRDP Project FreeRDPall versions before 3.31.0 (< 3.31.0), including urbdrc USB redirection channel usage
Estimated exposure
large≈100,000–1,000,000 FreeRDP-based client installations, with only the subset that enables USB redirection practically exposed — FreeRDP is the dominant open-source RDP client library, shipped in major Linux distributions and embedded in third-party remote desktop apps, but the vulnerable urbdrc USB redirection path must be explicitly enabled and requires a user to…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.

Weakness
CWE-457
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.