CVE-2025-68670: 
xrdp vulnerability analysis and mitigation

Overview

CVE-2025-68670 is an unauthenticated stack-based buffer overflow vulnerability in xrdp, an open-source RDP server. The flaw exists in versions before v0.10.5 and stems from improper bounds checking when processing user-supplied domain information during the RDP connection sequence. It was reported by Denis Skvortsov, a security researcher at Kaspersky, and publicly disclosed on January 27, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) per NVD, or 9.1 (Critical) per the GitHub Security Advisory (GitHub Advisory, Red Hat).

Technical details

The root cause is classified as CWE-121 (Stack-based Buffer Overflow) and CWE-787 (Out-of-bounds Write). The vulnerable code resides in xrdp/xrdp_login_wnd.c within the xrdp_wm_parse_domain_information() function, which failed to pass the destination buffer size as a parameter and used a hardcoded assumption of 256 bytes, allowing an attacker to supply an oversized domain string that overwrites the stack buffer and return address. The fix, applied in commit 488c8c7, adds a resultSize parameter to the function and replaces unsafe g_strncpy calls with strlcpy, along with a bounds check on the parsed position before copying (GitHub Commit). Exploitation requires no authentication and no user interaction, as the domain field is processed during the pre-authentication connection sequence. Stack canary protection (e.g., -fstack-protector-strong) can reduce exploitability but does not eliminate the risk, as a secondary information-disclosure vulnerability could be used to leak the canary value (GitHub Advisory).

Impact

Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary code on the target system with the privileges of the xrdp process. This results in complete compromise of confidentiality, integrity, and availability of the affected host. Because xrdp is commonly deployed to provide remote desktop access to Linux servers, exploitation could enable an attacker to gain a foothold for lateral movement within enterprise or cloud environments (GitHub Advisory, Red Hat).

Exploitability

As of the time of reporting, no public proof-of-concept exploit code is known to exist, and there is no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability was discovered and reported by Denis Skvortsov of Kaspersky, who published a detailed technical write-up in May 2026 (Securelist). The EPSS score is approximately 0.0024 (0.24%), reflecting a currently low probability of exploitation in the near term. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is network-accessible with no authentication or user interaction required, making it highly attractive for future weaponization.

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible hosts running xrdp (default TCP port 3389) using tools such as Shodan, Censys, or Nmap (nmap -sV -p 3389 <target>). Confirm the xrdp version is below 0.10.5.
  2. Craft malicious RDP connection request: Initiate an RDP connection to the target and supply an oversized domain string in the domain field of the RDP connection sequence (e.g., via a custom RDP client or by modifying the domain field in the Client Core Data structure of the RDP handshake).
  3. Trigger buffer overflow: The oversized domain string is passed to xrdp_wm_parse_domain_information() without proper bounds checking, overwriting the stack buffer and the saved return address in xrdp_login_wnd.c.
  4. Bypass stack canary (if present): If the xrdp binary was compiled with stack canary protection, a secondary information-disclosure vulnerability would be required to leak the canary value before overwriting the return address.
  5. Redirect execution flow: Craft the overflow payload to redirect the return address to attacker-controlled shellcode or a ROP chain, achieving arbitrary code execution as the xrdp process user (GitHub Advisory, Securelist).

Indicators of compromise

  • Network: Unexpected or malformed RDP connection attempts on TCP port 3389 with anomalously long domain field values; connections from unusual or external IP addresses to the xrdp service.
  • Logs: xrdp session logs (/var/log/xrdp.log, /var/log/xrdp-sesman.log) showing connection attempts with oversized or malformed domain strings; segmentation fault or crash entries in system logs (/var/log/syslog, journalctl) related to the xrdp process.
  • Process: Unexpected child processes spawned by xrdp (e.g., /bin/bash, sh, curl, wget, python) indicating post-exploitation activity; xrdp process crashing and restarting repeatedly (indicative of failed exploitation attempts).
  • File System: New or modified files in xrdp installation directories or /tmp; unexpected cron jobs, systemd units, or SSH authorized keys added after xrdp process activity.

Mitigation and workarounds

Upgrade xrdp to version 0.10.5 or later, which contains the patch for CVE-2025-68670 (xrdp v0.10.5 Release). Debian LTS users should apply the security update provided via DLA-4464-1, and Debian stable users should apply DSA-6123-1; SUSE and Mageia users should apply their respective vendor updates. As an interim workaround, restrict network access to the xrdp service (TCP port 3389) using firewall rules to limit exposure to trusted IP ranges only. Do not rely solely on stack canary protection as a mitigation on production systems, as it can potentially be bypassed with a secondary vulnerability (GitHub Advisory).

Community reactions

Kaspersky's Securelist published a detailed technical analysis of the vulnerability in May 2026, authored by the discoverer Denis Skvortsov, providing an in-depth walkthrough of the root cause and exploitation mechanics (Securelist). The vulnerability received coverage from The Hacker News in their weekly recap and was discussed across Reddit security communities and Mastodon, with community members highlighting the critical severity and pre-authentication nature of the flaw. SecureReading noted the risk to remote access infrastructure, emphasizing the potential for full Linux system compromise (SecureReading). Multiple Linux distributions including Debian, SUSE, Fedora, and Mageia issued security advisories and updated packages promptly after disclosure.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

xrdp: 0.9.21.1-1+deb12u2

Fixed

sid

xrdp: 0.10.1-4.1

Fixed

trixie

xrdp: 0.10.1-3.1+deb13u1

Fixed

Ubuntu

Fixed

bionic (esm-apps)

xrdp: 0.9.5-2ubuntu0.1~esm3

Fixed

devel

xrdp

Not Affected

focal (esm-apps)

xrdp: 0.9.12-1ubuntu0.1+esm2

Fixed

jammy

xrdp

Affected

jammy (esm-apps)

xrdp: 0.9.17-2ubuntu3+esm2

Fixed

noble

xrdp

Affected

noble (esm-apps)

xrdp: 0.9.24-4ubuntu0.1~esm1

Fixed

questing

xrdp: 0.10.1-3.1+deb13u1build0.25.10.1

Fixed

Alpine

Fixed

edge

xrdp: 0.10.5-r0

Fixed

v3.23

xrdp: 0.10.5-r0

Fixed

Source: This report was generated using AI

Related xrdp vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-54538HIGH7.5
  • xrdp logoxrdp
  • xrdp-selinux
NoYesJul 20, 2026
CVE-2026-55626HIGH7.3
  • xrdp logoxrdp
  • cpe:2.3:a:neutrinolabs:xrdp
NoYesJul 20, 2026
CVE-2026-55645MEDIUM6.5
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026
CVE-2026-55639MEDIUM5.3
  • xrdp logoxrdp
  • xrdp-debuginfo
NoYesJul 20, 2026
CVE-2026-55238MEDIUM5.3
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management