Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-40254

Опубликовано: 24 апр. 2026
Источник: nvd
CVSS3: 4.2
CVSS3: 6.1
EPSS Низкий

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path traversal filter in channels/drive/client/drive_file.c. The contains_dotdot() function catches ../ and ..\ mid-path but misses .. when it's the last component with no trailing separator. A rogue RDP server can read, list, or write files one directory above the client's shared folder through RDPDR requests. This requires the victim to connect with drive redirection enabled. Version 3.25.0 patches the issue.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
Версия до 3.25.0 (исключая)

EPSS

Процентиль: 10%
0.002
Низкий

4.2 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-193

Связанные уязвимости

CVSS3: 4.2
ubuntu
3 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path traversal filter in `channels/drive/client/drive_file.c`. The `contains_dotdot()` function catches `../` and `..\` mid-path but misses `..` when it's the last component with no trailing separator. A rogue RDP server can read, list, or write files one directory above the client's shared folder through RDPDR requests. This requires the victim to connect with drive redirection enabled. Version 3.25.0 patches the issue.

CVSS3: 6.1
redhat
3 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path traversal filter in `channels/drive/client/drive_file.c`. The `contains_dotdot()` function catches `../` and `..\` mid-path but misses `..` when it's the last component with no trailing separator. A rogue RDP server can read, list, or write files one directory above the client's shared folder through RDPDR requests. This requires the victim to connect with drive redirection enabled. Version 3.25.0 patches the issue.

CVSS3: 4.2
debian
3 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Versi ...

CVSS3: 6.1
fstec
3 месяца назад

Уязвимость функции contains_dotdot() RDP-клиента FreeRDP, позволяющая нарушителю читать и записывать произвольные файлы

CVSS3: 6.1
redos
около 1 месяца назад

Уязвимость freerdp3

EPSS

Процентиль: 10%
0.002
Низкий

4.2 Medium

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-193