Heap-based buffer overflow in xrdp - CVE-2026-32624
Published: April 17, 2026
xrdp
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service or modify memory.
The vulnerability exists due to heap-based buffer overflow in logon processing when handling a crafted excessively long username and domain name. A remote attacker can send a crafted excessively long username and domain name to cause a denial of service or modify memory.
Only systems where the domain_user_separator setting is configured in xrdp.ini are vulnerable.