CVE-2026-33689
EUVD-2026-2351617.04.2026, 21:16
xrdp is an open source RDP server. Versions through 0.10.5 have an out-of-bounds read vulnerability in the pre-authentication RDP message parsing logic. A remote, unauthenticated attacker can trigger this flaw by sending a specially crafted sequence of packets during the initial connection phase. This vulnerability results from insufficient validation of input buffer lengths before processing dynamic channel communication. Successful exploitation can lead to a denial-of-service (DoS) condition via a process crash or potential disclosure of sensitive information from the service's memory space. This issue has been fixed in version 0.10.6.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| neutrinolabs | xrdp | 𝑥 < 0.10.6 |
𝑥
= Vulnerable software versions
Debian Releases
Common Weakness Enumeration