PT-2026-33501 · Xrdp · Xrdp

Exploitintel

·

Published

2026-04-17

·

Updated

2026-04-20

·

CVE-2026-33516

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions xrdp versions prior to 0.10.6
Description An out-of-bounds read occurs during the RDP capability exchange phase when memory is accessed before validating the remaining buffer length. A remote, unauthenticated attacker can trigger this by sending a specially crafted Confirm Active PDU. This may result in a denial of service via process crash or the disclosure of sensitive information from the process memory.
Recommendations Update to version 0.10.6.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2026-06990
CVE-2026-33516

Affected Products

Xrdp