PT-2026-4947 · Xrdp+3 · Xrdp+3

CVE-2025-68670

·

Published

2025-01-01

·

Updated

2026-08-15

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xrdp versions prior to 0.10.5
Description xrdp contains an unauthenticated stack-based buffer overflow. The issue occurs during the pre-authentication Secure Settings Exchange via the Client Info PDU (T1210) when the xrdp wm parse domain information() function improperly checks the bounds of user domain information. Specifically, a 512-byte UTF-8 domain can be processed into a 256-byte buffer. An attacker can trigger this by using a domain name starting with " " followed by more than 256 UTF-8 bytes before the " " delimiter, often utilizing UTF-16 to UTF-8 conversion differences with Cyrillic characters to maximize expansion. This allows an attacker to overwrite the stack buffer and the return address to redirect execution flow and execute arbitrary code. Stack canaries provide partial protection but can be bypassed if the canary value is leaked. Real-world incidents have been reported where attackers used this to gain remote code execution, escalate privileges, and move laterally through networks.
Recommendations Upgrade to version 0.10.5. Do not rely on stack canary protection on production systems.

Exploit

Fix

DoS

RCE

Stack Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00962
CVE-2025-68670
GHSA-RWVG-GP87-GH6F
MGASA-2026-0037
OPENSUSE-SU-2026:10146-1
OPENSUSE-SU-2026:20167-1
SUSE-SU-2026:0404-1
SUSE-SU-2026:0433-1
SUSE-SU-2026:0477-1
USN-8476-1

Affected Products

Linuxmint
Red Os
Ubuntu
Xrdp