
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-35512 is a heap-based buffer overflow vulnerability in xrdp, an open-source RDP server, affecting all versions through 0.10.5. The flaw exists in the EGFX (Enhanced Graphics Framework) graphics dynamic virtual channel implementation and allows an out-of-bounds write via crafted PDUs due to insufficient validation of client-controlled size parameters. It was published on April 17, 2026, and fixed in version 0.10.6 released the same day. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 8.7 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-122 (Heap-based Buffer Overflow) and CWE-131 (Incorrect Calculation of Buffer Size), arising from the xrdp EGFX channel's failure to properly validate client-supplied size parameters before writing data to heap-allocated buffers (GitHub Advisory). An attacker sends specially crafted PDUs over the network to the RDP service, triggering an out-of-bounds write in the dynamic virtual channel processing code. Pre-authentication exploitation requires no credentials and can crash the xrdp process; post-authentication exploitation, which requires low-level privileges (a valid RDP account), may achieve remote code execution. The vulnerability was reported by researcher hessandrew and credited alongside exploitintel and smittix in the v0.10.6 release (xrdp v0.10.6 Release).
Pre-authentication exploitation results in a denial of service by crashing the xrdp process, disrupting remote desktop availability for all users. Post-authentication exploitation can lead to arbitrary code execution with the privileges of the xrdp daemon process, compromising confidentiality, integrity, and availability of the affected system (GitHub Advisory). If xrdp is running as root (configurations prior to 0.10.2 defaults), successful RCE could grant full administrative control; in non-privileged configurations (default since 0.10.2), impact is limited to the service account. Network-accessible RDP servers exposed to untrusted networks face the highest risk (Red Hat Bugzilla).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.86%, indicating a relatively low (but non-negligible) probability of exploitation in the near term. Detection coverage exists via Nessus plugin 307446 and Qualys detection ID 692288 (Feedly).
/var/log/xrdp.log) showing errors or crashes in EGFX/dynvc channel processing; repeated failed or anomalous session establishment attempts; core dump files generated by the xrdp process.core.*) in the xrdp working directory; new or modified files created by the xrdp service account following an RDP session.curl, wget, nc) or unusual process behavior following RDP session establishment; xrdp process restarting unexpectedly (indicating pre-auth crash exploitation).The primary remediation is to upgrade xrdp to version 0.10.6 or later, which contains the fix for CVE-2026-35512 along with several other security vulnerabilities (xrdp v0.10.6 Release). For systems that cannot be immediately patched, ensure xrdp runs as a non-privileged user by configuring the runtime_user and runtime_group settings in xrdp.ini — this has been the default since version 0.10.2 and significantly limits the impact of successful exploitation (GitHub Advisory). Additionally, restrict network access to the RDP service (TCP 3389) to trusted IP ranges using firewall rules to reduce the attack surface. Fedora and openSUSE have issued updated packages addressing this vulnerability (Feedly).
The vulnerability was disclosed by the xrdp maintainer (metalefty) via a GitHub Security Advisory on April 17, 2026, crediting researchers hessandrew, exploitintel, and smittix for discovery (xrdp v0.10.6 Release). Red Hat tracked the issue via Bugzilla and assigned it high severity, with downstream distributions including Fedora and openSUSE issuing updated packages shortly after disclosure (Red Hat Bugzilla). Security news aggregators and vulnerability tracking platforms (VulDB, CVEFeed, ENISA EUVD) indexed the vulnerability promptly, and Tenable released a Nessus detection plugin (307446) within days of disclosure.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."