PT-2026-33507 · Xrdp · Xrdp

Exploitintel

·

Published

2026-04-17

·

Updated

2026-05-19

·

CVE-2026-33689

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions xrdp versions prior to 0.10.6
Description An out-of-bounds read exists in the pre-authentication RDP message parsing logic. A remote, unauthenticated attacker can trigger this flaw by sending a specially crafted sequence of packets during the initial connection phase. The issue stems from insufficient validation of input buffer lengths before processing dynamic channel communication. This can result in a denial-of-service condition via a process crash or the potential disclosure of sensitive information from the service memory space.
Recommendations Update to version 0.10.6.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2026-06991
CVE-2026-33689
OPENSUSE-SU-2026:10816-1

Affected Products

Xrdp