Impact
FreeRDP versions prior to 3.29.0 do not validate RDPDR paths supplied by an RDP server, allowing a path traversal condition on the client side. The flaw enables an attacker to reference file system locations that are siblings to the configured shared root, thereby reading, writing, deleting, or enumerating files outside the intended shared directory. This represents a CWE‑22 exploitation scenario that could lead to unintended data disclosure or modification on the client machine.
Affected Systems
The vulnerability affects all builds of the FreeRDP client released before version 3.29.0. Any installation of FreeRDP that supports drive redirection is susceptible, regardless of platform, as the issue resides in the core path handling logic of the RDPDR component.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation data. The likely attack vector requires a malicious RDP server to be received by a user who initiates a remote desktop session; the attacker can then send non‑rooted paths in the drive redirection stream to gain unauthorized file system access on the client.
OpenCVE Enrichment