HIGH🇵🇱 Wersja polska

CVE-2026-32107

CVSS 8.8v3.1pub. 2026-04-17upd. 2026-04-27

xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop process. This improper privilege management could allow an authenticated local attacker to escalate privileges to root and execute arbitrary code on the system. An additional exploit would be needed to facilitate this. This issue has been fixed in version 0.10.6.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
  • Neutrinolabs Xrdp

    APP
    Neutrinolabs
    < 0.10.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCELPE
CWE
References

Related vulnerabilities

CVE-2026-41252CRITICAL9.8PL ✓same product

xrdp: heap buffer overflow w trybie vnc-any umożliwiający RCE przed uwierzytelnieniem

CVE-2026-32105CRITICAL9.3PL ✓same product

Brak weryfikacji podpisu MAC w Xrdp — podatność MITM w Classic RDP Security

CVE-2025-68670CRITICAL9.1PL ✓same product

Nieuwierzytelniony stack-based buffer overflow w xrdp (RCE)

CVE-2022-23478CRITICAL9.1PL ✓same product

Out of Bound Write w xrdp — zapis poza granicami bufora przez RDP

CVE-2022-23477CRITICAL9.1PL ✓same product

Buffer overflow w xrdp — funkcja audin_send_open()