PT-2026-33487 · Xrdp · Xrdp
Exploitintel
·
Published
2026-04-17
·
Updated
2026-05-19
·
CVE-2026-32105
CVSS v2.0
9.7
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:P |
Name of the Vulnerable Software and Affected Versions
xrdp versions prior to 0.10.6
Description
xrdp fails to implement verification for the Message Authentication Code (MAC) signature of encrypted RDP packets when the Classic RDP Security layer is used. Although signatures are generated by the sender, the receiving logic ignores the 8-byte integrity signature. This allows an unauthenticated attacker with man-in-the-middle (MITM) capabilities to modify encrypted traffic in transit without detection. This issue does not affect connections where the TLS security layer is enforced.
Recommendations
Update to version 0.10.6.
Configure xrdp.ini to enforce TLS security by setting
security layer=tls to ensure end-to-end integrity.Fix
LPE
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xrdp