Heap-based Buffer Overflow Vulnerability in xrdp by Neutrinolabs
CVE-2026-44178
8.8HIGH
What is CVE-2026-44178?
The xrdp software, an open-source Remote Desktop Protocol server, is susceptible to a heap-based buffer overflow stemming from its virtual channel forwarding feature. This vulnerability allows authenticated remote attackers to exploit the xrdp process by sending improperly sized virtual channel messages, resulting in heap memory corruption. Such exploitation can lead to denial of service or arbitrary code execution with the same privileges as the xrdp process. The issue has been addressed in version 0.10.6.1, emphasizing the importance of updating to maintain security.
Affected Version(s)
xrdp < 0.10.6.1
