Record summary

CVE-2020-4044 has a selected CVSS score of 7.5 (high); EIP currently links 1 curated repository PoC.

Description

The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them to capture any user credentials that are submitted to XRDP and approve or reject arbitrary login credentials. For xorgxrdp sessions in particular, this allows an unauthorized user to hijack an existing session. This is a buffer overflow attack, so there may be a risk of arbitrary code execution as well.

Description source: CVE List

Exploitation context

Available material

Curated repository PoCs
1

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List< 0.9.13.1affected

Proofs of concept

1

Curated repository PoCs

GitHubCVE-2025-68670Curated repository PoCby exploitintelStars: 8Exploit880 files

C · 16.0 MiB · linked to 5 vulnerabilities

GitHub

PoC details
Analysisdeepseek-v4-pro:cloud ·

Technical assessment

The artifact is a fully functional remote exploit for CVE-2025-68670, a pre-authentication stack-based buffer overflow in xrdp. It includes multiple Python scripts that implement a complete RDP handshake to deliver a malicious payload, overwrite the return address, and redirect execution to attacker-chosen addresses within the xrdp binary, achieving instruction pointer control.

Backdoor review

No backdoor observed in reviewed code

The supplied evidence consists of Python scripts and documentation for a CVE-2025-68670 proof-of-concept exploit targeting a stack-based buffer overflow in xrdp. The scripts implement a legitimate RDP handshake to deliver a malicious domain field, causing a crash or redirecting execution to specific addresses within the xrdp binary. No concealed backdoor, credential theft, persistence mechanism, or unrelated payload was observed. The behavior is consistent with a standard security research PoC.

ClassificationExploit
Model confidence98%
AuthenticationNot required
LanguagesPython
Target softwarexrdp
Attack typesStack-based Buffer OverflowRemote Code Execution
Evidence & reasoningClassification basis · observed behavior · safety review
Technical evidence

Classification basis and observed behavior

Classification basis

The primary artifact is classified as an exploit because it contains complete, functional code that actively exploits a vulnerability to achieve a security impact beyond simple detection. The script `exploit/exploit.py` is explicitly designed to 'Redirect execution to arbitrary functions in the binary's .text section' and 'Demonstrate... Instruction Pointer Control + Code Execution Redirection'. It performs a full RDP handshake, sends a crafted payload to trigger a stack-based buffer overflow, and overwrites the return address to hijack the control flow of the xrdp process.

exploit/exploit.py:1-28exploit/exploit.py:399-410exploit/exploit.py:563-567

Requirements

  • Network access to the target xrdp service on TCP port 3389.exploit/exploit.py:9
  • The target xrdp binary must be compiled without stack canary protection (-fno-stack-protector) and without PIE (-no-pie).README.md:170

Observed behavior

  • Initiates a TCP connection to the target and performs a complete, legitimate RDP protocol handshake (X.224, MCS Connect Initial, Channel Join) to reach the vulnerable code path.exploit/exploit.py:227-288
  • Constructs a malicious domain string containing a leading underscore, padding, and a double-underscore delimiter. This string is encoded as UTF-16LE and sent within the RDP TS_INFO_PACKET.exploit/exploit.py:163-220
  • The overflow overwrites saved callee-saved registers (RBX, RBP, R12-R15) and performs a 3-byte partial overwrite of the saved return address on the stack, redirecting execution to a chosen address in the binary's .text section (e.g., printf@plt).exploit/exploit.py:11-14README.md:340-349
  • Completes the RDP handshake by sending Confirm Active, Synchronize, Control, and Font List PDUs, which triggers the vulnerable function and the subsequent crash or code redirection.exploit/exploit.py:301-345
Safety-review evidence

Behaviors behind the backdoor verdict

Observables

Exploit Behavior
Payload withheldThis is the expected behavior for a PoC targeting CVE-2025-68670. The scripts send a crafted domain field to cause a crash or redirect execution to attacker-chosen addresses within the xrdp binary.exploit/exploit.py:34-35poc/crash_poc.py:5-14poc/control_flow_probe.py:1-8
Target Addresses
Payload withheldThese addresses are used to demonstrate instruction pointer control by redirecting execution to known functions within the vulnerable xrdp process. This is a standard technique for proving control flow hijacking.exploit/exploit.py:141-146poc/control_flow_probe.py:112-134
Bypass Attempt
Payload withheldThis is a secondary PoC targeting a related but distinct vulnerability. It does not introduce backdoor behavior; it attempts to trigger a heap overflow in a patched version of the software.poc/bypass_poc.py:1-48
Review boundaries

What the analysis did not establish

  • The evidence packet reports 23 binary files that were not analyzed, including compiled executables and core dumps. The analysis is based solely on the provided readable text files.
  • The analysis scope indicates 'complete_artifact_coverage: false', meaning not all files in the artifact were inspected.
  • 23 binary files were present in the artifact but were not analyzed per the evidence envelope's binary policy. Their contents could not be inspected for backdoor behavior.
  • The review is limited to the supplied text evidence; any behavior triggered only at runtime under specific conditions not described in the scripts would not be detected.
Model interpretation

This review is limited to the supplied PoC code and context. It does not assert that the code works or is safe to execute.

References

7