CVE-2026-91963
largeUninitialized Heap Memory Disclosure in FreeRDP USB Redirection Channel (pre-3.31.0)
FreeRDP versions before 3.31.0 disclose uninitialized heap memory via the urbdrc USB redirection channel (CWE-457). A malicious or compromised RDP server triggers failing USB transfer requests that cause the client to send back uninitialized heap contents. The leaked data can disclose heap addresses, defeating ASLR and enabling reliable remote code execution when chained with a memory corruption vulnerability. Any user of a FreeRDP-based client on a version before 3.31.0 who connects to an attacker-controlled server with USB redirection active is affected. No public proof-of-concept exists and the flaw is not listed in CISA's KEV catalog, so exploitation is not known to be occurring in the wild.
What to do: Upgrade FreeRDP to version 3.31.0 or later as soon as patched builds are available. If immediate upgrade is not possible, disable USB redirection entirely (do not enable the urbdrc channel, e.g., omit /usb options in xfreerdp) and restrict client connections to trusted, known RDP servers only. Administrators should also inventory downstream products that bundle FreeRDP (Linux distro packages, Remmina and similar clients, embedded appliance firmware) and apply vendor patches when released.
| FreeRDP Project FreeRDP | all versions before 3.31.0 (< 3.31.0), including urbdrc USB redirection channel usage |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.
- Weakness
- CWE-457
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.