CVE-2025-68670
published 2026-01-27CVE-2025-68670: xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper…
PriorityP264critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.32%
67.6th percentile
xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system. The vulnerability allows an attacker to overwrite the stack buffer and the return address, which could theoretically be used to redirect the execution flow. The impact of this vulnerability is lessened if a compiler flag has been used to build the xrdp executable with stack canary protection. If this is the case, a second vulnerability would need to be used to leak the stack canary value. Upgrade to version 0.10.5 to receive a patch. Additionally, do not rely on stack canary protection on production systems.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | xrdp | < xrdp 0.9.21.1-1+deb12u2 (bookworm) | xrdp 0.9.21.1-1+deb12u2 (bookworm) |
| neutrinolabs | xrdp | < 0.10.5 | 0.10.5 |
| neutrinolabs | xrdp | >= 0 < 0.9.21.1-1~deb11u3 | 0.9.21.1-1~deb11u3 |
| neutrinolabs | xrdp | >= 0 < 0.9.21.1-1+deb12u2 | 0.9.21.1-1+deb12u2 |
| neutrinolabs | xrdp | >= 0 < 0.10.1-3.1+deb13u1 | 0.10.1-3.1+deb13u1 |
| neutrinolabs | xrdp | >= 0 < 0.10.1-4.1 | 0.10.1-4.1 |
| ubuntu | xrdp | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is triggered pre-authentication during the Secure Settings Exchange phase (Client Info PDU / TS_INFO_PACKET), so any stack overflow crash or anomalous domain field in this phase should be flagged. ↗
- →Look for use of Cyrillic character U+041A ('К') repeated in the RDP domain field — the PoC specifically uses this character to craft the overflow payload due to its UTF-16 to UTF-8 size properties. ↗
- ·Stack canary protection reduces exploitability but does not eliminate it — a second vulnerability to leak the canary value would be needed. Do not rely on stack canaries as a sole mitigation in production. ↗
- ·The vulnerable function xrdp_wm_parse_domain_information uses a hardcoded 256-byte resultIP buffer while accepting domain input up to 512 bytes — the mismatch is the root cause and is present in all xrdp versions before 0.10.5 / 0.9.27 / 0.10.4.1. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.1CRITICAL
vendor_ubuntu6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
xrdp vulnerabilities
vendor_ubuntu·2026-06-25·CVSS 6.5
CVE-2023-40184 [MEDIUM] xrdp vulnerabilities
Title: xrdp vulnerabilities
Summary: Several security issues were fixed in xrdp.
It was discovered that xrdp incorrectly handled bounds checking when
processing user domain information during the connection sequence. An
unauthenticated remote attacker could use this issue to cause xrdp to
crash, resulting in a denial of service, or possibly execute arbitrary
code. (CVE-2025-68670)
It was discovered that xrdp did not correctly enforce the maximum number of
login attempts configured by the MaxLoginRetry parameter. A remote attacker
could use this issue to perform an unlimited number of login attempts.
(CVE-2024-39917)
It was discovered that xrdp did not perform bounds checking when accessing
font glyphs. Since some of this data is controllable by the user, a remote
attacker could use thi
Debian
CVE-2025-68670: xrdp - xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticat...
vendor_debian·2025·CVSS 9.1
CVE-2025-68670 [CRITICAL] CVE-2025-68670: xrdp - xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticat...
xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system. The vulnerability allows an attacker to overwrite the stack buffer and the return address, which could theoretically be used to redirect the execution flow. The impact of this vulnerability is lessened if a compiler flag has been used to build the xrdp executable with stack canary protection. If this is the case, a second vulnerability would need to be used to leak the stack canary value. Upgrade to version 0.10.5 to receive a patch. Additiona
OSV
CVE-2025-68670: xrdp is an open source RDP server
osv·2026-01-27·CVSS 9.8
CVE-2025-68670 [CRITICAL] CVE-2025-68670: xrdp is an open source RDP server
xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system. The vulnerability allows an attacker to overwrite the stack buffer and the return address, which could theoretically be used to redirect the execution flow. The impact of this vulnerability is lessened if a compiler flag has been used to build the xrdp executable with stack canary protection. If this is the case, a second vulnerability would need to be used to leak the stack canary value. Upgrade to version 0.10.5 to receive a patch. Additiona
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More
blogs_hackernews·2026-05-11·CVSS 9.3
CVE-2026-6973 [CRITICAL] ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More
Rough Monday.
Somebody poisoned a trusted download again, somebody else turned cloud servers into public housing, and a few crews are still getting into boxes with bugs that should’ve died years ago — the same old holes, same lazy access paths, same “how the hell is this still open” feeling. One report this week basically reads like a guy tripped over root access by accident and decided to stay there.
The weird part is how normal this all sounds now. Fake updates. Quiet backdoors. Remote tools are used like skeleton keys. Forum rats swapping st
Securelist
CVE-2025-68670: discovering an RCE vulnerability in xrdp
blogs_securelist·2026-05-08·CVSS 9.8
CVE-2025-68670 [CRITICAL] CVE-2025-68670: discovering an RCE vulnerability in xrdp
Denis Skvortsov
Dmitry Shmoylov
Table of Contents
Client data transmission via RDP
CVE-2025-68670: an RCE vulnerability in xrdp
PoC
Protection against vulnerability exploitation
Vulnerability remediation timeline
Conclusion
Authors
Denis Skvortsov
Dmitry Shmoylov
In addition to KasperskyOS-powered solutions, Kaspersky offers various utility software to streamline business operations. For instance, users of Kaspersky Thin Client , an operating system for thin clients, can also purchase Kaspersky USB Redirector, a module that expands the capabilities of the xrdp remote desktop server for Linux. This module enables access to local USB devices, such as flash drives, tokens, smart cards, and printers, within a remote desktop session – all while maintaining connection security.
We t
Wiz
CVE-2025-68670 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.1
CVE-2025-68670 [CRITICAL] CVE-2025-68670 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-68670 :
xrdp vulnerability analysis and mitigation
xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system. The vulnerability allows an attacker to overwrite the stack buffer and the return address, which could theoretically be used to redirect the execution flow. The impact of this vulnerability is lessened if a compiler flag has been used to build the xrdp executable with stack canary protection. If this is the case, a second vulnerability would need to be used to leak the stack cana
Bugzilla
CVE-2025-68670 xrdp: xrdp: Remote code execution via unauthenticated stack-based buffer overflow
bugzilla·2026-01-27·CVSS 9.8
CVE-2025-68670 [CRITICAL] CVE-2025-68670 xrdp: xrdp: Remote code execution via unauthenticated stack-based buffer overflow
CVE-2025-68670 xrdp: xrdp: Remote code execution via unauthenticated stack-based buffer overflow
xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system. The vulnerability allows an attacker to overwrite the stack buffer and the return address, which could theoretically be used to redirect the execution flow. The impact of this vulnerability is lessened if a compiler flag has been used to build the xrdp executable with stack canary protection. If this is the case, a second vulnerability would need
2026-01-27
Published