Beveiligingsadvies

CVE-2026-91963

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-09-15 15:18:16
Laatst bijgewerkt 2026-09-15 15:58:06
Toegewezen door VulnCheck
CVSS-score 7.1
Status PUBLISHED

Beschrijving

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.