cve-2026-91963
MEDIUM CVSS 6.5 opencve
Description
FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.
Timeline
- Published
- 2026-09-15 16:17 UTC
- Last Modified
- 2026-09-23
CVSS Details
CVSS details not available.
Affected Products
No product information available.
CVSS metrics
| Version | Base | Severity | Vector | Exploitability | Impact | Source |
|---|---|---|---|---|---|---|
| 4.0 | 7.1 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
mitre | ||
| 3.1 | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
mitre | ||
| 4.0 | 7.1 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
nvd | ||
| 3.1 | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
nvd | ||
| 4.0 | 7.1 | HIGH | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
opencve | ||
| 3.1 | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
opencve | ||
| 3.1 | 8.8 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
redhat |
References
No references available.
Linked Vulnerabilities
{
"cve": "CVE-2026-91963",
"enrichment": {
"affected": [
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "semver",
"value": "[2.0.0,3.0.0)"
}
},
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "semver",
"value": "[3.0.0,3.31.0)"
}
},
{
"platform": null,
"status": "unaffected",
"versions": {
"scheme": "semver",
"value": "3.31.0"
}
}
],
"enrichment": {
"confidence": 100.0,
"confidence_source": "inferred",
"scores": [
{
"score": 100.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "FreeRDP",
"source": "cna",
"vendor": "FreeRDP"
},
"product": "freerdp",
"vendor": "freerdp"
},
{
"configurations": [
{
"platform": null,
"status": "affected",
"versions": {
"scheme": "semver",
"value": "[0,3.31.0)"
}
},
{
"platform": null,
"status": "unaffected",
"versions": {
"scheme": "semver",
"value": "3.31.0"
}
}
],
"enrichment": {
"confidence": 100.0,
"confidence_source": "inferred",
"scores": [
{
"score": 100.0,
"source": "inferred"
},
{
"score": 100.0,
"source": "matching"
}
]
},
"original": {
"product": "FreeRDP",
"source": "cna",
"vendor": "FreeRDP"
},
"product": "freerdp",
"vendor": "freerdp"
}
],
"created": "2026-09-16T03:45:08.115575+00:00",
"updated": "2026-09-20T16:30:18.233011+00:00",
"vendors": [
"freerdp",
"freerdp$PRODUCT$freerdp"
]
},
"epss": {
"score": 0.0064
},
"mitre": {
"cpes": [
"cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*"
],
"created": "2026-09-15T15:18:16.675000+00:00",
"description": "FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 6.5,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
},
"cvssV4_0": {
"score": 7.1,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
}
},
"mitre_repo_path": "cves/2026/91xxx/CVE-2026-91963.json",
"references": [
"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq",
"https://www.vulncheck.com/advisories/freerdp-2.0.0-through-3.30.0-uninitialized-heap-memory-disclosure-via-urbdrc"
],
"title": "FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc",
"updated": "2026-09-15T15:58:06.421000+00:00",
"vendors": [
"freerdp",
"freerdp$PRODUCT$freerdp"
],
"weaknesses": [
"CWE-457"
]
},
"nvd": {
"cpes": [
"cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*"
],
"created": "2026-09-15T16:17:51.907000+00:00",
"description": "FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 6.5,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
},
"cvssV4_0": {
"score": 7.1,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"nvd_repo_path": "2026/CVE-2026-91963.json",
"references": [
"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq",
"https://www.vulncheck.com/advisories/freerdp-2.0.0-through-3.30.0-uninitialized-heap-memory-disclosure-via-urbdrc"
],
"title": null,
"updated": "2026-09-23T20:08:36.160000+00:00",
"vendors": [
"freerdp",
"freerdp$PRODUCT$freerdp"
],
"weaknesses": [
"CWE-457"
]
},
"opencve": {
"changes": [
{
"created": "2026-09-15T15:30:00+00:00",
"data": [
{
"details": {
"new": "FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.",
"old": null
},
"type": "description"
},
{
"details": {
"new": "FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc",
"old": null
},
"type": "title"
},
{
"details": [
"freerdp",
"freerdp$PRODUCT$freerdp"
],
"type": "first_time"
},
{
"details": {
"added": [
"CWE-457"
],
"removed": []
},
"type": "weaknesses"
},
{
"details": {
"added": [
"cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*"
],
"removed": []
},
"type": "cpes"
},
{
"details": {
"added": [
"freerdp",
"freerdp$PRODUCT$freerdp"
],
"removed": []
},
"type": "vendors"
},
{
"details": {
"added": [
"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq",
"https://www.vulncheck.com/advisories/freerdp-2.0.0-through-3.30.0-uninitialized-heap-memory-disclosure-via-urbdrc"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {
"cvssV3_1": {
"score": 6.5,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
},
"cvssV4_0": {
"score": 7.1,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "e9374fb7-dd87-4c1e-a3df-4001d0fc1ae1"
},
{
"created": "2026-09-15T16:30:00+00:00",
"data": [
{
"details": {
"added": {
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "poc",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"removed": {},
"updated": {}
},
"type": "metrics"
}
],
"id": "0515b799-e463-46cc-86aa-eda376f46eec"
},
{
"created": "2026-09-16T00:15:00+00:00",
"data": [
{
"details": {
"added": [
"CWE-824"
],
"removed": []
},
"type": "weaknesses"
},
{
"details": {
"added": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-91963",
"https://www.cve.org/CVERecord?id=CVE-2026-91963"
],
"removed": []
},
"type": "references"
},
{
"details": {
"added": {},
"removed": {},
"updated": {
"threat_severity": {
"new": "Important",
"old": null
}
}
},
"type": "metrics"
}
],
"id": "78b9cdae-9221-41a7-895c-1acf2aa722ed"
}
],
"cpes": {
"data": [
"cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*"
],
"providers": [
"mitre",
"nvd"
]
},
"created": {
"data": "2026-09-15T15:18:16+00:00",
"provider": "redhat"
},
"description": {
"data": "FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.",
"provider": "mitre"
},
"metrics": {
"cvssV2_0": {
"data": {},
"provider": null
},
"cvssV3_0": {
"data": {},
"provider": null
},
"cvssV3_1": {
"data": {
"score": 6.5,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
},
"provider": "mitre"
},
"cvssV4_0": {
"data": {
"score": 7.1,
"vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
},
"provider": "mitre"
},
"epss": {
"data": {
"score": 0.0064
},
"provider": "first"
},
"kev": {
"data": {},
"provider": null
},
"ssvc": {
"data": {
"options": {
"Automatable": "no",
"Exploitation": "poc",
"Technical Impact": "partial"
},
"version": "2.0.3"
},
"provider": "vulnrichment"
},
"threat_severity": {
"data": "Important",
"provider": "redhat"
}
},
"references": {
"data": [
"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq",
"https://nvd.nist.gov/vuln/detail/CVE-2026-91963",
"https://www.cve.org/CVERecord?id=CVE-2026-91963",
"https://www.vulncheck.com/advisories/freerdp-2.0.0-through-3.30.0-uninitialized-heap-memory-disclosure-via-urbdrc"
],
"providers": [
"mitre",
"nvd",
"redhat",
"vulnrichment"
]
},
"title": {
"data": "FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc",
"provider": "mitre"
},
"updated": {
"data": "2026-09-15T16:17:51.907000+00:00",
"provider": "nvd"
},
"vendors": {
"data": [
"freerdp",
"freerdp$PRODUCT$freerdp"
],
"providers": [
"mitre",
"nvd",
"enrichment"
]
},
"weaknesses": {
"data": [
"CWE-457",
"CWE-824"
],
"providers": [
"mitre",
"nvd",
"redhat"
]
}
},
"redhat": {
"cpes": [],
"created": "2026-09-15T15:18:16+00:00",
"description": "A flaw was found in FreeRDP. An uninitialized heap memory disclosure vulnerability exists in the urbdrc USB redirection channel. A malicious Remote Desktop Protocol (RDP) server can exploit this by inducing failing USB transfers, allowing it to read uninitialized heap memory from the client. This information disclosure can defeat Address Space Layout Randomization (ASLR), potentially enabling remote code execution when chained with other memory corruption vulnerabilities.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {
"score": 8.8,
"vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
},
"threat_severity": "Important"
},
"redhat_repo_path": "2026/CVE-2026-91963.json",
"references": [
"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq",
"https://nvd.nist.gov/vuln/detail/CVE-2026-91963",
"https://www.cve.org/CVERecord?id=CVE-2026-91963",
"https://www.vulncheck.com/advisories/freerdp-2.0.0-through-3.30.0-uninitialized-heap-memory-disclosure-via-urbdrc"
],
"title": "FreeRDP: FreeRDP: Remote code execution via uninitialized heap memory disclosure",
"updated": "2026-09-15T15:18:16+00:00",
"vendors": [],
"weaknesses": [
"CWE-824"
]
},
"vulnrichment": {
"cpes": [],
"created": "2026-09-15T15:18:16.675000+00:00",
"description": "FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.",
"metrics": {
"cvssV2_0": {},
"cvssV3_0": {},
"cvssV3_1": {},
"cvssV4_0": {},
"kev": {},
"ssvc": {
"options": {
"Automatable": "no",
"Exploitation": "poc",
"Technical Impact": "partial"
},
"version": "2.0.3"
}
},
"references": [
"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq"
],
"title": "FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc",
"updated": "2026-09-15T15:57:47.331000+00:00",
"vendors": [],
"vulnrichment_repo_path": "2026/91xxx/CVE-2026-91963.json",
"weaknesses": []
}
}
Enrichment data
Aggregated bundle (all enrichments)