Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities. | |
| Title | FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc | |
| First Time appeared |
Freerdp
Freerdp freerdp |
|
| Weaknesses | CWE-457 | |
| CPEs | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Freerdp
Freerdp freerdp |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-15T15:58:06.421Z
Reserved: 2026-09-15T11:08:44.670Z
Link: CVE-2026-91963
Updated: 2026-09-15T15:57:47.331Z
Status : Received
Published: 2026-09-15T16:17:51.907
Modified: 2026-09-15T16:17:51.907
Link: CVE-2026-91963
No data.
OpenCVE Enrichment
No data.
-
CWE-457
Use of Uninitialized Variable