Description
xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters, allowing an out-of-bounds write via crafted PDUs. Pre-authentication exploitation can crash the process, while post-authentication exploitation may achieve remote code execution. This issue has been fixed in version 0.10.6. If users are unable to immediately update, they should run xrdp as a non-privileged user (default since 0.10.2) to limit the impact of successful exploitation.
References (2)
Core 2
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-jg6p-7fg8-9hh6
X_Refsource_Misc x_refsource_misc
https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6
Scores
CVSS v3
8.8
EPSS
0.0058
EPSS Percentile
43.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-122
Status
published
Products (1)
neutrinolabs/xrdp
< 0.10.6 (2 CPE variants)
Published
Apr 17, 2026
Tracked Since
Apr 18, 2026