FreeRDP before 3.28.0 treats lines beginning with forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, or expose local filesystems without user interaction.
References
| Link | Resource |
|---|---|
| https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rq8f-9xjh-pr3m | Vendor Advisory |
| https://www.vulncheck.com/advisories/freerdp-rdp-file-parser-remote-code-execution-via-cli-options | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-07-20 22:17
Updated : 2026-07-29 15:21
NVD link : CVE-2026-64624
Mitre link : CVE-2026-64624
CVE.ORG link : CVE-2026-64624
JSON object : View
Products Affected
freerdp
- freerdp
CWE
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
