cve-2026-91963

MEDIUM CVSS 6.5 opencve
Description

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.

Timeline
Published
2026-09-15 16:17 UTC
Last Modified
2026-09-23
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N mitre
3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N mitre
4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X nvd
3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N nvd
4.0 7.1 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N opencve
3.1 6.5 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N opencve
3.1 8.8 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H redhat
References

No references available.

Linked Vulnerabilities

{
  "cve": "CVE-2026-91963",
  "enrichment": {
    "affected": [
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[2.0.0,3.0.0)"
            }
          },
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[3.0.0,3.31.0)"
            }
          },
          {
            "platform": null,
            "status": "unaffected",
            "versions": {
              "scheme": "semver",
              "value": "3.31.0"
            }
          }
        ],
        "enrichment": {
          "confidence": 100.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 100.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "FreeRDP",
          "source": "cna",
          "vendor": "FreeRDP"
        },
        "product": "freerdp",
        "vendor": "freerdp"
      },
      {
        "configurations": [
          {
            "platform": null,
            "status": "affected",
            "versions": {
              "scheme": "semver",
              "value": "[0,3.31.0)"
            }
          },
          {
            "platform": null,
            "status": "unaffected",
            "versions": {
              "scheme": "semver",
              "value": "3.31.0"
            }
          }
        ],
        "enrichment": {
          "confidence": 100.0,
          "confidence_source": "inferred",
          "scores": [
            {
              "score": 100.0,
              "source": "inferred"
            },
            {
              "score": 100.0,
              "source": "matching"
            }
          ]
        },
        "original": {
          "product": "FreeRDP",
          "source": "cna",
          "vendor": "FreeRDP"
        },
        "product": "freerdp",
        "vendor": "freerdp"
      }
    ],
    "created": "2026-09-16T03:45:08.115575+00:00",
    "updated": "2026-09-20T16:30:18.233011+00:00",
    "vendors": [
      "freerdp",
      "freerdp$PRODUCT$freerdp"
    ]
  },
  "epss": {
    "score": 0.0064
  },
  "mitre": {
    "cpes": [
      "cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-09-15T15:18:16.675000+00:00",
    "description": "FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6.5,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
      },
      "cvssV4_0": {
        "score": 7.1,
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
      }
    },
    "mitre_repo_path": "cves/2026/91xxx/CVE-2026-91963.json",
    "references": [
      "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq",
      "https://www.vulncheck.com/advisories/freerdp-2.0.0-through-3.30.0-uninitialized-heap-memory-disclosure-via-urbdrc"
    ],
    "title": "FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc",
    "updated": "2026-09-15T15:58:06.421000+00:00",
    "vendors": [
      "freerdp",
      "freerdp$PRODUCT$freerdp"
    ],
    "weaknesses": [
      "CWE-457"
    ]
  },
  "nvd": {
    "cpes": [
      "cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*"
    ],
    "created": "2026-09-15T16:17:51.907000+00:00",
    "description": "FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 6.5,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
      },
      "cvssV4_0": {
        "score": 7.1,
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      }
    },
    "nvd_repo_path": "2026/CVE-2026-91963.json",
    "references": [
      "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq",
      "https://www.vulncheck.com/advisories/freerdp-2.0.0-through-3.30.0-uninitialized-heap-memory-disclosure-via-urbdrc"
    ],
    "title": null,
    "updated": "2026-09-23T20:08:36.160000+00:00",
    "vendors": [
      "freerdp",
      "freerdp$PRODUCT$freerdp"
    ],
    "weaknesses": [
      "CWE-457"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2026-09-15T15:30:00+00:00",
        "data": [
          {
            "details": {
              "new": "FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "new": "FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc",
              "old": null
            },
            "type": "title"
          },
          {
            "details": [
              "freerdp",
              "freerdp$PRODUCT$freerdp"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "CWE-457"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*"
              ],
              "removed": []
            },
            "type": "cpes"
          },
          {
            "details": {
              "added": [
                "freerdp",
                "freerdp$PRODUCT$freerdp"
              ],
              "removed": []
            },
            "type": "vendors"
          },
          {
            "details": {
              "added": [
                "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq",
                "https://www.vulncheck.com/advisories/freerdp-2.0.0-through-3.30.0-uninitialized-heap-memory-disclosure-via-urbdrc"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV3_1": {
                  "score": 6.5,
                  "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
                },
                "cvssV4_0": {
                  "score": 7.1,
                  "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "e9374fb7-dd87-4c1e-a3df-4001d0fc1ae1"
      },
      {
        "created": "2026-09-15T16:30:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "no",
                    "Exploitation": "poc",
                    "Technical Impact": "partial"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "0515b799-e463-46cc-86aa-eda376f46eec"
      },
      {
        "created": "2026-09-16T00:15:00+00:00",
        "data": [
          {
            "details": {
              "added": [
                "CWE-824"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "https://nvd.nist.gov/vuln/detail/CVE-2026-91963",
                "https://www.cve.org/CVERecord?id=CVE-2026-91963"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {},
              "removed": {},
              "updated": {
                "threat_severity": {
                  "new": "Important",
                  "old": null
                }
              }
            },
            "type": "metrics"
          }
        ],
        "id": "78b9cdae-9221-41a7-895c-1acf2aa722ed"
      }
    ],
    "cpes": {
      "data": [
        "cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "created": {
      "data": "2026-09-15T15:18:16+00:00",
      "provider": "redhat"
    },
    "description": {
      "data": "FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {
          "score": 6.5,
          "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
        },
        "provider": "mitre"
      },
      "cvssV4_0": {
        "data": {
          "score": 7.1,
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"
        },
        "provider": "mitre"
      },
      "epss": {
        "data": {
          "score": 0.0064
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "no",
            "Exploitation": "poc",
            "Technical Impact": "partial"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": "Important",
        "provider": "redhat"
      }
    },
    "references": {
      "data": [
        "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq",
        "https://nvd.nist.gov/vuln/detail/CVE-2026-91963",
        "https://www.cve.org/CVERecord?id=CVE-2026-91963",
        "https://www.vulncheck.com/advisories/freerdp-2.0.0-through-3.30.0-uninitialized-heap-memory-disclosure-via-urbdrc"
      ],
      "providers": [
        "mitre",
        "nvd",
        "redhat",
        "vulnrichment"
      ]
    },
    "title": {
      "data": "FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc",
      "provider": "mitre"
    },
    "updated": {
      "data": "2026-09-15T16:17:51.907000+00:00",
      "provider": "nvd"
    },
    "vendors": {
      "data": [
        "freerdp",
        "freerdp$PRODUCT$freerdp"
      ],
      "providers": [
        "mitre",
        "nvd",
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-457",
        "CWE-824"
      ],
      "providers": [
        "mitre",
        "nvd",
        "redhat"
      ]
    }
  },
  "redhat": {
    "cpes": [],
    "created": "2026-09-15T15:18:16+00:00",
    "description": "A flaw was found in FreeRDP. An uninitialized heap memory disclosure vulnerability exists in the urbdrc USB redirection channel. A malicious Remote Desktop Protocol (RDP) server can exploit this by inducing failing USB transfers, allowing it to read uninitialized heap memory from the client. This information disclosure can defeat Address Space Layout Randomization (ASLR), potentially enabling remote code execution when chained with other memory corruption vulnerabilities.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {
        "score": 8.8,
        "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"
      },
      "threat_severity": "Important"
    },
    "redhat_repo_path": "2026/CVE-2026-91963.json",
    "references": [
      "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq",
      "https://nvd.nist.gov/vuln/detail/CVE-2026-91963",
      "https://www.cve.org/CVERecord?id=CVE-2026-91963",
      "https://www.vulncheck.com/advisories/freerdp-2.0.0-through-3.30.0-uninitialized-heap-memory-disclosure-via-urbdrc"
    ],
    "title": "FreeRDP: FreeRDP: Remote code execution via uninitialized heap memory disclosure",
    "updated": "2026-09-15T15:18:16+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-824"
    ]
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2026-09-15T15:18:16.675000+00:00",
    "description": "FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "no",
          "Exploitation": "poc",
          "Technical Impact": "partial"
        },
        "version": "2.0.3"
      }
    },
    "references": [
      "https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hw7p-5h2r-83gq"
    ],
    "title": "FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc",
    "updated": "2026-09-15T15:57:47.331000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2026/91xxx/CVE-2026-91963.json",
    "weaknesses": []
  }
}
Enrichment data
View JSON API Download JSON