xrdp is an open source RDP server. In versions through 0.10.5, the session execution component did not properly handle an error during the privilege drop process. This improper privilege management could allow an authenticated local attacker to escalate privileges to root and execute arbitrary code on the system. An additional exploit would be needed to facilitate this. This issue has been fixed in version 0.10.6.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HNeutrinolabs Xrdp
APPNeutrinolabs< 0.10.6
Related vulnerabilities
xrdp: heap buffer overflow w trybie vnc-any umożliwiający RCE przed uwierzytelnieniem
Brak weryfikacji podpisu MAC w Xrdp — podatność MITM w Classic RDP Security
Nieuwierzytelniony stack-based buffer overflow w xrdp (RCE)
Out of Bound Write w xrdp — zapis poza granicami bufora przez RDP
Buffer overflow w xrdp — funkcja audin_send_open()