Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-32107

Опубликовано: 17 апр. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop process. This improper privilege management could allow an authenticated local attacker to escalate privileges to root and execute arbitrary code on the system. An additional exploit would be needed to facilitate this. This issue has been fixed in version 0.10.6.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:neutrinolabs:xrdp:*:*:*:*:*:*:*:*
Версия до 0.10.6 (исключая)

EPSS

Процентиль: 5%
0.00159
Низкий

8.8 High

CVSS3

Дефекты

CWE-273

Связанные уязвимости

CVSS3: 8.8
ubuntu
4 месяца назад

xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop process. This improper privilege management could allow an authenticated local attacker to escalate privileges to root and execute arbitrary code on the system. An additional exploit would be needed to facilitate this. This issue has been fixed in version 0.10.6.

CVSS3: 7
redhat
4 месяца назад

xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop process. This improper privilege management could allow an authenticated local attacker to escalate privileges to root and execute arbitrary code on the system. An additional exploit would be needed to facilitate this. This issue has been fixed in version 0.10.6.

CVSS3: 8.8
debian
4 месяца назад

xrdp is an open source RDP server. In versions through 0.10.5, the ses ...

CVSS3: 8.8
fstec
4 месяца назад

Уязвимость сервера XRDP, связанная с недостатками разграничения доступа, позволяющая нарушителю повысить свои привилегии до уровня root и выполнить произвольный код

EPSS

Процентиль: 5%
0.00159
Низкий

8.8 High

CVSS3

Дефекты

CWE-273