PT-2026-33498 · Xrdp · Xrdp

Exploitintel

·

Published

2026-04-17

·

Updated

2026-05-19

·

CVE-2026-32623

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions xrdp versions prior to 0.10.6
Description A heap-based buffer overflow exists in the NeutrinoRDP module. When proxying RDP sessions to another server, the module does not properly validate the size of reassembled fragmented virtual channel data against its allocated memory buffer. A malicious downstream RDP server or an attacker performing a Man-in-the-Middle attack could exploit this to cause memory corruption, potentially resulting in a Denial of Service (DoS) or Remote Code Execution (RCE). This issue only affects environments where the NeutrinoRDP module has been explicitly compiled and enabled.
Recommendations Update to version 0.10.6. As a temporary workaround, disable the NeutrinoRDP module if it was explicitly enabled.

Fix

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-06987
CVE-2026-32623
OPENSUSE-SU-2026:10816-1

Affected Products

Xrdp