<Vulnerability name="CVE-2026-67295">
    <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
    <ThreatSeverity>Moderate</ThreatSeverity>
    <PublicDate>2026-08-01T12:22:18</PublicDate>
    <Bugzilla id="2509998" url="https://bugzilla.redhat.com/show_bug.cgi?id=2509998" xml:lang="en:us">
FreeRDP: FreeRDP: Unauthorized File Access via Drive Redirection Vulnerability
    </Bugzilla>
    <CVSS3 status="draft">
        <CVSS3BaseScore>6.3</CVSS3BaseScore>
        <CVSS3ScoringVector>CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L</CVSS3ScoringVector>
    </CVSS3>
    <CWE>CWE-22</CWE>
    <Details xml:lang="en:us" source="Mitre">
FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. A malicious RDP server can read, write, delete, and enumerate files in sibling directories by sending non-rooted paths that bypass the shared-root boundary check.
    </Details>
    <Details xml:lang="en:us" source="Red Hat">
A flaw was found in FreeRDP, an open-source implementation of the Remote Desktop Protocol (RDP). This vulnerability allows a malicious RDP server to bypass security checks during drive redirection. By sending specially crafted paths, the server can access, read, write, delete, and list files in directories outside the intended shared folder on the client's system. This could lead to unauthorized access and manipulation of sensitive data.
    </Details>
    <Statement xml:lang="en:us">
This issue is classified as Moderate severity because exploitation requires a user to connect to a malicious or compromised RDP server with drive redirection enabled, allowing the server to bypass directory boundary checks to read, modify, or delete files outside the shared folder on the client system.
    </Statement>
    <Mitigation xml:lang="en:us">
To mitigate this vulnerability, disable drive redirection when connecting to untrusted RDP servers. This can typically be configured within the FreeRDP client settings or by avoiding the use of the `/drive` or `/home-drive` options when initiating an RDP session. Disabling drive redirection prevents the server from manipulating local file paths.
    </Mitigation>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:10">
        <ProductName>Red Hat Enterprise Linux 10</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:6">
        <ProductName>Red Hat Enterprise Linux 6</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:7">
        <ProductName>Red Hat Enterprise Linux 7</ProductName>
        <FixState>Out of support scope</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:8">
        <ProductName>Red Hat Enterprise Linux 8</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <PackageState cpe="cpe:/o:redhat:enterprise_linux:9">
        <ProductName>Red Hat Enterprise Linux 9</ProductName>
        <FixState>Fix deferred</FixState>
        <PackageName>freerdp</PackageName>
    </PackageState>
    <References xml:lang="en:us">
https://www.cve.org/CVERecord?id=CVE-2026-67295
https://nvd.nist.gov/vuln/detail/CVE-2026-67295
https://github.com/FreeRDP/FreeRDP/commit/8d3b86022f0d71aefa7bd2e466d2d391693a41b3
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8xqm-wp3f-rfp9
https://www.vulncheck.com/advisories/freerdp-before-path-traversal-via-drive-redirection
    </References>
</Vulnerability>