PT-2026-33501 · Xrdp · Xrdp

·

CVE-2026-33516

·

Published

2026-04-17

·

Updated

2026-04-20

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions xrdp versions prior to 0.10.6
Description An out-of-bounds read occurs during the RDP capability exchange phase when memory is accessed before validating the remaining buffer length. A remote, unauthenticated attacker can trigger this by sending a specially crafted Confirm Active PDU. This may result in a denial of service via process crash or the disclosure of sensitive information from the process memory.
Recommendations Update to version 0.10.6.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06990
CVE-2026-33516
GHSA-RVH9-9WM3-28C7

Affected Products

Xrdp