Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-91963

Опубликовано: 15 сент. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.

A flaw was found in FreeRDP. An uninitialized heap memory disclosure vulnerability exists in the urbdrc USB redirection channel. A malicious Remote Desktop Protocol (RDP) server can exploit this by inducing failing USB transfers, allowing it to read uninitialized heap memory from the client. This information disclosure can defeat Address Space Layout Randomization (ASLR), potentially enabling remote code execution when chained with other memory corruption vulnerabilities.

Меры по смягчению последствий

To reduce exposure, avoid connecting to untrusted RDP servers or disable the FreeRDP USB redirection channel if it is not required. When using the xfreerdp client, ensure that USB redirection is not enabled. This can be done by omitting the /usb or /usb-redir command-line options, or by explicitly disabling the urbdrc channel through FreeRDP configuration if available. Disabling this feature will prevent the redirection of USB devices to the remote session.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpAffected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-824
https://bugzilla.redhat.com/show_bug.cgi?id=2533930FreeRDP: FreeRDP: Remote code execution via uninitialized heap memory disclosure

EPSS

Процентиль: 49%
0.0064
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
3 дня назад

[GHSA-hw7p-5h2r-83gq: Disclosure of uninitialized heap memory in the urbdrc USB redirection path]

CVSS3: 6.5
nvd
3 дня назад

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.

CVSS3: 6.5
debian
3 дня назад

FreeRDP versions before 3.31.0 contain an uninitialized heap memory di ...

CVSS3: 6.5
github
3 дня назад

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.

EPSS

Процентиль: 49%
0.0064
Низкий

8.8 High

CVSS3