PT-2026-61741 · Freerdp · Freerdp
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.28.0
Description
FreeRDP treats lines starting with a forward slash in RDP files as raw command-line options, which exposes the entire CLI parser surface to untrusted files. This allows attackers to use malicious RDP files containing options such as
/rdp2tcp, /cert:ignore, or /drive to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.Recommendations
Update FreeRDP to version 3.28.0 or later.
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp