xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system. The vulnerability allows an attacker to overwrite the stack buffer and the return address, which could theoretically be used to redirect the execution flow. The impact of this vulnerability is lessened if a compiler flag has been used to build the xrdp executable with stack canary protection. If this is the case, a second vulnerability would need to be used to leak the stack canary value. Upgrade to version 0.10.5 to receive a patch. Additionally, do not rely on stack canary protection on production systems.
Conclusion & alert: CVE-2025-68670 is rated Moderate Risk (61/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.32%). Core evidence: EPSS rose +1.16% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.16% | 1.32% | +1.16% |
| 2 | 2026-05-13 | 0.11% | 0.16% | +0.05% |
| 3 | 2026-02-18 | — | 0.11% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.1 | 3.1 | CRITICAL |
|
3.9 | 5.2 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2025-68670: 1 source package rows (xrdp); 15 state rows across 2 repos (3.23-community, edge-community); fixed 2, open 13. | https://security.alpinelinux.org/vuln/CVE-2025-68670 |
debian
|
not yet assigned | CVE-2025-68670 not yet assigned priority: Debian including 1 source packages (xrdp), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2025-68670 |
suse
|
high | — | https://www.suse.com/security/cve/CVE-2025-68670/ |
ubuntu
|
medium | CVE-2025-68670 medium priority: Ubuntu including 1 source packages (xrdp), 8 status rows across 8 suites (bionic, focal, jammy, noble, questing, trusty, upstream, xenial): needs-triage 8. | https://ubuntu.com/security/CVE-2025-68670 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| neutrinolabs | xrdp | < 0.10.5 | cpe:2.3:a:neutrinolabs:xrdp:*:*:*:*:*:*:*:* |
| debian | debian_linux | 11.0 | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |