Security Advisory

CVE-2026-91963

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-15 15:18:16
Last updated 2026-09-15 15:58:06
Assigner VulnCheck
CVSS score 7.1
State PUBLISHED

Description

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.