PT-2026-4947 · Xrdp+3 · Xrdp+3
CVE-2025-68670
·
Published
2025-01-01
·
Updated
2026-08-15
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
xrdp versions prior to 0.10.5
Description
xrdp contains an unauthenticated stack-based buffer overflow. The issue occurs during the pre-authentication Secure Settings Exchange via the Client Info PDU (T1210) when the
xrdp wm parse domain information() function improperly checks the bounds of user domain information. Specifically, a 512-byte UTF-8 domain can be processed into a 256-byte buffer. An attacker can trigger this by using a domain name starting with " " followed by more than 256 UTF-8 bytes before the " " delimiter, often utilizing UTF-16 to UTF-8 conversion differences with Cyrillic characters to maximize expansion. This allows an attacker to overwrite the stack buffer and the return address to redirect execution flow and execute arbitrary code. Stack canaries provide partial protection but can be bypassed if the canary value is leaked. Real-world incidents have been reported where attackers used this to gain remote code execution, escalate privileges, and move laterally through networks.Recommendations
Upgrade to version 0.10.5.
Do not rely on stack canary protection on production systems.
Exploit
Fix
DoS
RCE
Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linuxmint
Red Os
Ubuntu
Xrdp