Impact
FreeRDP versions earlier than 3.28.0 incorrectly parse lines beginning with a forward slash in RDP files as command‑line arguments. This flaw enables attackers to embed options such as /rdp2tcp, /cert:ignore, or /drive, which can cause arbitrary executable code to run, bypass certificate validation, or expose local file systems. The underlying weakness is CWE‑88, an improperly controlled input that directly influences program execution. The result is a high‑severity vulnerability allowing an attacker to gain remote code execution without user interaction.
Affected Systems
FreeRDP releases predating version 3.28.0 are affected. The flaw exists in all FreeRDP deployments that use the RDP file parser without applying newer security patches.
Risk and Exploitability
The CVSS base score of 8.5 underlines the severe impact of this vulnerability, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild at present. The flaw is not listed in the CISA KEV catalog, suggesting no known large‑scale exploitation. Attackers would likely need to deliver a malicious RDP file to a user or application that automatically parses it; the lack of user interaction required means a successful exploit could occur simply by placing a crafted file in a monitored directory or transferring it over a network share.
OpenCVE Enrichment