PT-2026-33501 · Xrdp · Xrdp
Exploitintel
·
Published
2026-04-17
·
Updated
2026-04-20
·
CVE-2026-33516
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
xrdp versions prior to 0.10.6
Description
An out-of-bounds read occurs during the RDP capability exchange phase when memory is accessed before validating the remaining buffer length. A remote, unauthenticated attacker can trigger this by sending a specially crafted Confirm Active PDU. This may result in a denial of service via process crash or the disclosure of sensitive information from the process memory.
Recommendations
Update to version 0.10.6.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Xrdp