
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68670 is an unauthenticated stack-based buffer overflow vulnerability in xrdp, an open-source RDP server. The flaw exists in versions before v0.10.5 and stems from improper bounds checking when processing user-supplied domain information during the RDP connection sequence. It was reported by Denis Skvortsov, a security researcher at Kaspersky, and publicly disclosed on January 27, 2026. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical) per NVD, or 9.1 (Critical) per the GitHub Security Advisory (GitHub Advisory, Red Hat).
The root cause is classified as CWE-121 (Stack-based Buffer Overflow) and CWE-787 (Out-of-bounds Write). The vulnerable code resides in xrdp/xrdp_login_wnd.c within the xrdp_wm_parse_domain_information() function, which failed to pass the destination buffer size as a parameter and used a hardcoded assumption of 256 bytes, allowing an attacker to supply an oversized domain string that overwrites the stack buffer and return address. The fix, applied in commit 488c8c7, adds a resultSize parameter to the function and replaces unsafe g_strncpy calls with strlcpy, along with a bounds check on the parsed position before copying (GitHub Commit). Exploitation requires no authentication and no user interaction, as the domain field is processed during the pre-authentication connection sequence. Stack canary protection (e.g., -fstack-protector-strong) can reduce exploitability but does not eliminate the risk, as a secondary information-disclosure vulnerability could be used to leak the canary value (GitHub Advisory).
Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary code on the target system with the privileges of the xrdp process. This results in complete compromise of confidentiality, integrity, and availability of the affected host. Because xrdp is commonly deployed to provide remote desktop access to Linux servers, exploitation could enable an attacker to gain a foothold for lateral movement within enterprise or cloud environments (GitHub Advisory, Red Hat).
As of the time of reporting, no public proof-of-concept exploit code is known to exist, and there is no confirmed evidence of in-the-wild exploitation (Feedly). The vulnerability was discovered and reported by Denis Skvortsov of Kaspersky, who published a detailed technical write-up in May 2026 (Securelist). The EPSS score is approximately 0.0024 (0.24%), reflecting a currently low probability of exploitation in the near term. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is network-accessible with no authentication or user interaction required, making it highly attractive for future weaponization.
nmap -sV -p 3389 <target>). Confirm the xrdp version is below 0.10.5.domain field in the Client Core Data structure of the RDP handshake).xrdp_wm_parse_domain_information() without proper bounds checking, overwriting the stack buffer and the saved return address in xrdp_login_wnd.c./var/log/xrdp.log, /var/log/xrdp-sesman.log) showing connection attempts with oversized or malformed domain strings; segmentation fault or crash entries in system logs (/var/log/syslog, journalctl) related to the xrdp process./bin/bash, sh, curl, wget, python) indicating post-exploitation activity; xrdp process crashing and restarting repeatedly (indicative of failed exploitation attempts)./tmp; unexpected cron jobs, systemd units, or SSH authorized keys added after xrdp process activity.Upgrade xrdp to version 0.10.5 or later, which contains the patch for CVE-2025-68670 (xrdp v0.10.5 Release). Debian LTS users should apply the security update provided via DLA-4464-1, and Debian stable users should apply DSA-6123-1; SUSE and Mageia users should apply their respective vendor updates. As an interim workaround, restrict network access to the xrdp service (TCP port 3389) using firewall rules to limit exposure to trusted IP ranges only. Do not rely solely on stack canary protection as a mitigation on production systems, as it can potentially be bypassed with a secondary vulnerability (GitHub Advisory).
Kaspersky's Securelist published a detailed technical analysis of the vulnerability in May 2026, authored by the discoverer Denis Skvortsov, providing an in-depth walkthrough of the root cause and exploitation mechanics (Securelist). The vulnerability received coverage from The Hacker News in their weekly recap and was discussed across Reddit security communities and Mastodon, with community members highlighting the critical severity and pre-authentication nature of the flaw. SecureReading noted the risk to remote access infrastructure, emphasizing the potential for full Linux system compromise (SecureReading). Multiple Linux distributions including Debian, SUSE, Fedora, and Mageia issued security advisories and updated packages promptly after disclosure.
Fix availability across major Linux distributions and their releases.
bookworm
xrdp: 0.9.21.1-1+deb12u2
sid
xrdp: 0.10.1-4.1
trixie
xrdp: 0.10.1-3.1+deb13u1
bionic (esm-apps)
xrdp: 0.9.5-2ubuntu0.1~esm3
devel
xrdp
focal (esm-apps)
xrdp: 0.9.12-1ubuntu0.1+esm2
jammy
xrdp
jammy (esm-apps)
xrdp: 0.9.17-2ubuntu3+esm2
noble
xrdp
noble (esm-apps)
xrdp: 0.9.24-4ubuntu0.1~esm1
questing
xrdp: 0.10.1-3.1+deb13u1build0.25.10.1
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."