Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-64624

Опубликовано: 20 июл. 2026
Источник: redhat
CVSS3: 7.3
EPSS Низкий

Описание

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

A flaw in FreeRDP's file parser incorrectly treats lines starting with a forward slash (/) as command-line options. If a victim opens a maliciously crafted .rdp file, an attacker can silently inject CLI flags to execute arbitrary code, expose local filesystems, or bypass certificate validation.

Отчет

This Important flaw in FreeRDP for RHEL allows an attacker to execute arbitrary code, bypass certificate validation, or expose local filesystems if a user opens a crafted .rdp file. This occurs because the parser improperly treats lines starting with a forward slash (/) as command-line options.

Меры по смягчению последствий

To mitigate this issue, users should avoid opening RDP files from untrusted or unknown sources. Ensure SELinux remains in enforcing mode. This is the most important existing Red Hat safeguard for this CVE, confining what an exploited FreeRDP process can access.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpAffected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-88
https://bugzilla.redhat.com/show_bug.cgi?id=2503096FreeRDP: FreeRDP: Arbitrary code execution via malicious RDP files

EPSS

Процентиль: 8%
0.0018
Низкий

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
12 дней назад

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

CVSS3: 7.8
nvd
12 дней назад

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

CVSS3: 7.8
debian
12 дней назад

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP ...

CVSS3: 7.8
github
12 дней назад

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

EPSS

Процентиль: 8%
0.0018
Низкий

7.3 High

CVSS3