Remote Code Execution Vulnerability in FreeRDP by FreeRDP
CVE-2026-64624
8.5HIGH
What is CVE-2026-64624?
FreeRDP versions before 3.28.0 are susceptible to a serious vulnerability that allows attackers to bypass security measures through manipulation of RDP files. By crafting RDP files with specific command-line options, such as /rdp2tcp, /cert:ignore, or /drive, attackers can execute arbitrary commands and potentially expose local filesystems without any user intervention. This flaw highlights the risks associated with untrusted RDP files and underscores the need for stringent validation and security practices.
Affected Version(s)
FreeRDP 0 < 3.28.0
