CVE-2026-91963: FreeRDP 2.0.0 through 3.30.0 Uninitialized Heap Memory Disclosure via urbdrc
FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeRDPto a version that resolves this vulnerability.Fixed in 3.31.0 - Compensating control
If upgrading is not immediately possible, mitigate by disabling or blocking access to the FreeRDP urbdrc USB redirection channel so the malicious RDP server cannot trigger failing USB transfers in the urbdrc USB redirection channel.
Event History
Frequently Asked Questions
Who is exposed to this issue?
FreeRDP clients running versions 2.0.0 through 3.30.0 are exposed when they connect to a malicious RDP server and use the urbdrc USB redirection channel.
What does an attacker need to exploit it?
An attacker needs to operate or control a malicious RDP server that a vulnerable FreeRDP client connects to. No client-side privileges are required, but user interaction is required because the client must initiate the RDP connection.
What is the impact of successful exploitation?
The malicious server can cause failing USB transfers that disclose uninitialized heap memory from the client. This can defeat ASLR and may enable remote code execution when combined with a separate memory-corruption vulnerability.
Which versions address the issue?
The issue affects versions before 3.31.0. Upgrading to FreeRDP 3.31.0 or later addresses the affected version range.