Use of uninitialized resource in FreeRDP - #VU146598

 

Use of uninitialized resource in FreeRDP - #VU146598

Published: September 1, 2026


Vulnerability identifier: #VU146598
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-908
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to use of uninitialized resource in the urbdrc USB redirection path when handling failed or short USB control transfer IN completions. A remote attacker can issue crafted IN transfers through a malicious RDP server to disclose sensitive information.

USB redirection must be active and a USB device must be redirected for exploitation to succeed.


Affected software

FreeRDP

Remediation

Install security update from vendor's website.

FreeRDP - update to 3.31.0

External References

Related Security Bulletins