CVE-2026-67295

Public on 2026-08-01
Modified on 2026-09-10
Description
FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. A malicious RDP server can read, write, delete, and enumerate files in sibling directories by sending non-rooted paths that bypass the shared-root boundary check.
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
6.3
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core freerdp 2026-08-31 ALAS2-2026-3887 Fixed
Amazon Linux 2023 freerdp 2026-08-31 ALAS2023-2026-2111 Fixed
Amazon Linux 2027 Preview freerdp Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 6.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L