Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mx9v-6x7q-rjc2

Опубликовано: 01 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.3

Описание

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. A malicious RDP server can read, write, delete, and enumerate files in sibling directories by sending non-rooted paths that bypass the shared-root boundary check.

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. A malicious RDP server can read, write, delete, and enumerate files in sibling directories by sending non-rooted paths that bypass the shared-root boundary check.

EPSS

Процентиль: 16%
0.00245
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.3
nvd
2 дня назад

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. A malicious RDP server can read, write, delete, and enumerate files in sibling directories by sending non-rooted paths that bypass the shared-root boundary check.

CVSS3: 6.3
debian
2 дня назад

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR ...

EPSS

Процентиль: 16%
0.00245
Низкий

5.3 Medium

CVSS4

6.3 Medium

CVSS3

Дефекты

CWE-22