PT-2026-34838 · Freerdp+1 · Freerdp+1

·

CVE-2026-40254

·

Published

2026-04-23

·

Updated

2026-07-20

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.25.0
Description An off-by-one error exists in the path traversal filter within channels/drive/client/drive file.c. The contains dotdot() function fails to detect .. when it is the final component of a path without a trailing separator, although it correctly identifies ../ and .. mid-path. A malicious RDP server can exploit this to read, list, or write files one directory above the client's shared folder via RDPDR requests, provided the client connects with drive redirection enabled.
Recommendations Update to version 3.25.0.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09693
CVE-2026-40254
GHSA-3XPJ-M4HX-8VMX
OPENSUSE-SU-2026:10832-1
OPENSUSE-SU-2026:21116-1
SUSE-SU-2026:22194-1
USN-8561-1

Affected Products

Freerdp
Red Os