Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67295

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 6.3
EPSS Низкий

Описание

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. A malicious RDP server can read, write, delete, and enumerate files in sibling directories by sending non-rooted paths that bypass the shared-root boundary check.

A flaw was found in FreeRDP, an open-source implementation of the Remote Desktop Protocol (RDP). This vulnerability allows a malicious RDP server to bypass security checks during drive redirection. By sending specially crafted paths, the server can access, read, write, delete, and list files in directories outside the intended shared folder on the client's system. This could lead to unauthorized access and manipulation of sensitive data.

Отчет

This issue is classified as Moderate severity because exploitation requires a user to connect to a malicious or compromised RDP server with drive redirection enabled, allowing the server to bypass directory boundary checks to read, modify, or delete files outside the shared folder on the client system.

Меры по смягчению последствий

To mitigate this vulnerability, disable drive redirection when connecting to untrusted RDP servers. This can typically be configured within the FreeRDP client settings or by avoiding the use of the /drive or /home-drive options when initiating an RDP session. Disabling drive redirection prevents the server from manipulating local file paths.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpFix deferred
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpOut of support scope
Red Hat Enterprise Linux 8freerdpFix deferred
Red Hat Enterprise Linux 9freerdpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2509998FreeRDP: FreeRDP: Unauthorized File Access via Drive Redirection Vulnerability

EPSS

Процентиль: 16%
0.00245
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
ubuntu
около 1 месяца назад

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. A malicious RDP server can read, write, delete, and enumerate files in sibling directories by sending non-rooted paths that bypass the shared-root boundary check.

CVSS3: 6.3
nvd
около 1 месяца назад

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. A malicious RDP server can read, write, delete, and enumerate files in sibling directories by sending non-rooted paths that bypass the shared-root boundary check.

CVSS3: 6.3
debian
около 1 месяца назад

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR ...

CVSS3: 6.3
github
около 1 месяца назад

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. A malicious RDP server can read, write, delete, and enumerate files in sibling directories by sending non-rooted paths that bypass the shared-root boundary check.

EPSS

Процентиль: 16%
0.00245
Низкий

6.3 Medium

CVSS3