Off-by-one in FreeRDP - CVE-2026-40254

 

Off-by-one in FreeRDP - CVE-2026-40254

Published: April 23, 2026


Vulnerability identifier: #VU126890
CSH Severity: Low
CVSS v4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40254
CWE-ID: CWE-193
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information and modify files outside the intended shared drive root.

The vulnerability exists due to an off-by-one error in contains_dotdot() in channels/drive/client/drive_file.c when processing RDPDR drive redirection I/O requests containing a terminal .. path component. A remote attacker can send specially crafted RDPDR requests to disclose sensitive information and modify files outside the intended shared drive root.

User interaction is required, and exploitation requires the victim to connect to a rogue RDP server with drive redirection enabled.


Affected software

FreeRDP

How to mitigate CVE-2026-40254

Install security update from vendor's website.

FreeRDP - update to 3.25.0

External References

Related Security Bulletins