Impact
xrdp performs an out‑of‑bounds read when parsing Client Security Data in the GCC Conference Create Request during the initial connection sequence. A remote, unauthenticated attacker can send a malicious RDP packet that bypasses length validation, allowing the server process to read a few bytes beyond the declared data block. These bytes may contain sensitive memory contents that could be combined with other vulnerabilities, leading to an information leak.
Affected Systems
The open‑source RDP server xrdp from neutrinolabs is impacted. Versions 0.10.6 and earlier are vulnerable; the fix is incorporated in release 0.10.6.1 and newer.
Risk and Exploitability
The CVSS score of 5.3 places the flaw in the moderate range, with an EPSS score of <1%, and it is not listed in the CISA KEV catalog. Exploitation requires remote, unauthenticated access via the RDP protocol, which is frequently exposed over the Internet or internal networks. The lack of bounds checks enables the attacker to read memory beyond the intended boundary, making this a viable vector for information disclosure and a potential stepping stone to other attacks if coupled with additional system weaknesses.
OpenCVE Enrichment