Out-of-bounds read in xrdp - CVE-2026-33516
Published: April 17, 2026
xrdp
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information or cause a denial of service.
The vulnerability exists due to out-of-bounds read in the RDP capability exchange handling when processing a specially crafted Confirm Active PDU. A remote attacker can send a specially crafted Confirm Active PDU to disclose sensitive information or cause a denial of service.
The issue can be triggered during the pre-authentication phase.