Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-91963

FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirection channel. A malicious RDP server can induce failing USB transfers to read uninitialized heap memory from the client, defeating ASLR and enabling remote code execution when chained with memory corruption vulnerabilities.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 49.3%
CVSS Severity
CVSS v3 Score 6.5


Contact Us

Shodan ® - All rights reserved