Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-41252

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The issue occurs during the handling of RFB protocol color map messages from a VNC server, where incoming color indices are not properly validated. A malicious VNC server can exploit this flaw by sending crafted messages with out-of-range values, leading to an out-of-bounds write on the heap. This memory corruption can result in a denial of service (DoS) or potentially allow remote code execution (RCE) prior to authentication. This issue has been fixed in version 0.10.6.1.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 62.4%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-41252


Contact Us

Shodan ® - All rights reserved