FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path traversal filter in `channels/drive/client/drive_file.c`. The `contains_dotdot()` function catches `../` and `..\` mid-path but misses `..` when it's the last component with no trailing separator. A rogue RDP server can read, list, or write files one directory above the client's shared folder through RDPDR requests. This requires the victim to connect with drive redirection enabled. Version 3.25.0 patches the issue.
References
| Link | Resource |
|---|---|
| https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3xpj-m4hx-8vmx | Exploit Mitigation Vendor Advisory |
| https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3xpj-m4hx-8vmx | Exploit Mitigation Vendor Advisory |
Configurations
History
27 Apr 2026, 17:44
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Freerdp
Freerdp freerdp |
|
| CPE | cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:* | |
| References | () https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3xpj-m4hx-8vmx - Exploit, Mitigation, Vendor Advisory |
24 Apr 2026, 12:17
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3xpj-m4hx-8vmx - |
24 Apr 2026, 03:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-24 03:16
Updated : 2026-06-17 10:44
NVD link : CVE-2026-40254
Mitre link : CVE-2026-40254
CVE.ORG link : CVE-2026-40254
JSON object : View
Products Affected
freerdp
- freerdp
CWE
CWE-193
Off-by-one Error
