Out-of-bounds write in FreeRDP - #VU146582
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an out-of-bounds write in urb_send_current_frame_number_result() in the urbdrc client channel when processing a crafted USB redirection message from an RDP server. A remote attacker can send a specially crafted 28-byte message to cause a denial of service.
User interaction is required to start an RDP connection with USB redirection enabled and a device actually redirected.