GHSA-4vxc-ggfg-5366HighCVSS 7.8

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line...

Published
July 21, 2026
Last Modified
July 21, 2026

🔗 CVE IDs covered (1)

📋 Description

FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.

🔗 References (4)