MEDIUM

CVE-2026-91951

2026-09-15 CVSS v3.1
CVSS
6.5

Description

FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_current_frame_number_result() function. A malicious RDP server can send a crafted 28-byte USB redirection message to trigger a 4-byte write past the allocated 16-byte buffer, causing denial of service when verbose asserts are enabled.

Weakness (CWE)

CWE-617 Reachable Assertion

EPSS Score

0.35%
Probability of exploitation in next 30 days
28.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE