PT-2026-33507 · Xrdp · Xrdp

·

CVE-2026-33689

·

Published

2026-04-17

·

Updated

2026-05-19

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions xrdp versions prior to 0.10.6
Description An out-of-bounds read exists in the pre-authentication RDP message parsing logic. A remote, unauthenticated attacker can trigger this flaw by sending a specially crafted sequence of packets during the initial connection phase. The issue stems from insufficient validation of input buffer lengths before processing dynamic channel communication. This can result in a denial-of-service condition via a process crash or the potential disclosure of sensitive information from the service memory space.
Recommendations Update to version 0.10.6.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06991
CVE-2026-33689
GHSA-92MR-6WPP-27JJ
OPENSUSE-SU-2026:10816-1

Affected Products

Xrdp