Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Ashley Newson

#35506of 56,338
7.8Total CVSS
Vulnerabilities · 1
PT-2020-6234
7.8
2020-06-30
Xrdp · Xrdp-Sesman · CVE-2020-4044
**Name of the Vulnerable Software and Affected Versions** xrdp-sesman versions prior to 0.9.13.1 **Description** The issue is related to a buffer overflow attack that can crash the xrdp-sesman service by connecting over port 3350 and supplying a malicious payload. Once the service is down, an unprivileged attacker can start an imposter sesman service, allowing them to capture user credentials submitted to XRDP, approve or reject arbitrary login credentials, and potentially hijack existing xorgxrdp sessions. This may also pose a risk of arbitrary code execution. **Recommendations** For versions prior to 0.9.13.1, update to version 0.9.13.1 or later to resolve the issue. As a temporary workaround, consider restricting access to port 3350 to minimize the risk of exploitation.