Remote Code Execution Vulnerability in FreeRDP by FreeRDP
CVE-2026-64624

8.5HIGH

Key Information:

Vendor

Freerdp

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-64624?

FreeRDP versions before 3.28.0 are susceptible to a serious vulnerability that allows attackers to bypass security measures through manipulation of RDP files. By crafting RDP files with specific command-line options, such as /rdp2tcp, /cert:ignore, or /drive, attackers can execute arbitrary commands and potentially expose local filesystems without any user intervention. This flaw highlights the risks associated with untrusted RDP files and underscores the need for stringent validation and security practices.

Affected Version(s)

FreeRDP 0 < 3.28.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

DavidKorczynski
.