Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-35512

Опубликовано: 17 апр. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters, allowing an out-of-bounds write via crafted PDUs. Pre-authentication exploitation can crash the process, while post-authentication exploitation may achieve remote code execution. This issue has been fixed in version 0.10.6. If users are unable to immediately update, they should run xrdp as a non-privileged user (default since 0.10.2) to limit the impact of successful exploitation.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:neutrinolabs:xrdp:*:*:*:*:*:*:*:*
Версия до 0.10.6 (исключая)

EPSS

Процентиль: 45%
0.00583
Низкий

8.8 High

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 8.8
ubuntu
4 месяца назад

xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters, allowing an out-of-bounds write via crafted PDUs. Pre-authentication exploitation can crash the process, while post-authentication exploitation may achieve remote code execution. This issue has been fixed in version 0.10.6. If users are unable to immediately update, they should run xrdp as a non-privileged user (default since 0.10.2) to limit the impact of successful exploitation.

CVSS3: 8.8
debian
4 месяца назад

xrdp is an open source RDP server. Versions through 0.10.5 have a heap ...

CVSS3: 10
fstec
4 месяца назад

Уязвимость сервера XRDP, связанная с переполнением буфера в динамической памяти, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 45%
0.00583
Низкий

8.8 High

CVSS3

Дефекты

CWE-122