FreeRDP是FreeRDP团队开源的一款开源的远程桌面协议(RDP)的实现。 FreeRDP 3.28.0之前版本存在命令注入漏洞,该漏洞源于RDP文件中以正斜杠开头的行被视为原始命令行选项,攻击者可制作恶意RDP文件,使用/rdp2tcp、/cert:ignore或/drive选项,无需用户交互即可执行任意命令、绕过证书验证或暴露本地文件系统。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-64620 | 9.8 CRITICAL | FreeRDP before 3.28.0 Heap Buffer Overflow via crypto_rsa_common |
| CVE-2026-64621 | 7.3 HIGH | FreeRDP before 3.28.0 Double-Free via selectedmonitors |
No comments yet