PT-2026-61003 · Xrdp · Xrdp

CVE-2026-41252

·

Published

2026-07-08

·

Updated

2026-07-21

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions xrdp versions prior to 0.10.6.1
Description A missing bounds check in the server occurs when operating in vnc-any mode during the handling of RFB protocol color map messages from a VNC server. Because incoming color indices are not properly validated, a malicious VNC server can send crafted messages with out-of-range values, leading to a heap-based buffer overflow. This memory corruption can result in a denial of service (DoS) or potentially allow remote code execution (RCE) prior to authentication.
Recommendations Update to version 0.10.6.1.

Exploit

Fix

RCE

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41252
GHSA-W5VG-6QMV-J63J

Affected Products

Xrdp