Usbredir · Usbredir · CVE-2021-3700
**Name of the Vulnerable Software and Affected Versions**
usbredir versions prior to 0.11.0
**Description**
A use-after-free issue was found in the `usbredirparser serialize()` function in `usbredirparser/usbredirparser.c`. This occurs when serializing large amounts of buffered write data, particularly in cases of slow or blocked destinations. The exploitation of this issue could allow an attacker to access confidential data, compromise data integrity, and cause a denial of service.
**Recommendations**
For versions prior to 0.11.0, update to version 0.11.0 or later to resolve the issue.
As a temporary workaround, consider disabling the `usbredirparser serialize()` function until a patch is available.