← Späť na vyhľadávanie CVE

CVE-2026-40254

FreeRDP

Popis

FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path traversal filter in `channels/drive/client/drive_file.c`. The `contains_dotdot()` function catches `../` and `..\` mid-path but misses `..` when it-s the last component with no trailing separator. A rogue RDP server can read, list, or write files one directory above the client-s shared folder through RDPDR requests. This requires the victim to connect with drive redirection enabled. Version 3.25.0 patches the issue.

CVSS 4.2EPSS 0.2%Riziko 0.43
Zobraziť zdroj
Zverejnené
2026-04-24 03:16:11
Dotknuté verzie
<3.25.0
Typ
Package
Vektor
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N