Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-64624

Опубликовано: 20 июл. 2026
Источник: debian
EPSS Низкий

Описание

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
freerdp3unfixedpackage
freerdp2removedpackage

Примечания

  • https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rq8f-9xjh-pr3m

  • With 3.28.0 the option has been disabled by default, issue when handling

  • an untrusted .rdp file

EPSS

Процентиль: 8%
0.0018
Низкий

Связанные уязвимости

CVSS3: 7.8
ubuntu
2 месяца назад

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

CVSS3: 7.3
redhat
2 месяца назад

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

CVSS3: 7.8
nvd
2 месяца назад

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

CVSS3: 8.4
redos
19 дней назад

Уязвимость freerdp3

CVSS3: 8.4
redos
19 дней назад

Уязвимость freerdp3

EPSS

Процентиль: 8%
0.0018
Низкий