CVE-2025-68670Disclosure(debian / debian_linux)

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch debian debian_linux systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system. The vulnerability allows an attacker to overwrite the stack buffer and the return address, which could theoretically be used to redirect the execution flow. The impact of this vulnerability is lessened if a compiler flag has been used to build the xrdp executable with stack canary protection. If this is the case, a second vulnerability would need to be used to leak the stack canary value. Upgrade to version 0.10.5 to receive a patch. Additionally, do not rely on stack canary protection on production systems.

8.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121CWE-787

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • xrdp

Threat summary

  • Active exploitation appears in 3 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 25 mentions across 11 observed days

What's happening

  • Active exploitation reported across 3 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 10 signals
  • Technical details provided in 25 signals
  • Disclosure: 12 classified signals
  • Peaked 4d ago at 9 mentions (2026-05-08); latest day: 2
  • 25 total mentions across 11 days

Affected systems

Products
debian_linuxxrdp

1 version affected across 2 products

Deep dive

Activity timeline25 mentions / 11d
02579Mentions · 2026-01-27: 2Mentions · 2026-01-28: 2Mentions · 2026-01-29: 1Mentions · 2026-02-05: 1Mentions · 2026-02-08: 3Mentions · 2026-02-09: 1Mentions · 2026-05-08: 9Mentions · 2026-05-09: 2Mentions · 2026-05-10: 1Mentions · 2026-05-11: 1Mentions · 2026-05-12: 2PoC Mentioned / Linked · 2026-05-09: 1PoC Mentioned / Linked · 2026-05-10: 1PoC Mentioned / Linked · 2026-05-11: 1Exploit Tool / Code · 2026-05-11: 1Active Exploitation · 2026-05-08: 2Active Exploitation · 2026-05-09: 1Patch / Workaround · 2026-01-27: 1Patch / Workaround · 2026-01-28: 2Patch / Workaround · 2026-01-29: 1Patch / Workaround · 2026-02-08: 1Patch / Workaround · 2026-05-08: 3Patch / Workaround · 2026-05-09: 1Patch / Workaround · 2026-05-12: 1Technical Details · 2026-01-27: 2Technical Details · 2026-01-28: 2Technical Details · 2026-01-29: 1Technical Details · 2026-02-05: 1Technical Details · 2026-02-08: 3Technical Details · 2026-02-09: 1Technical Details · 2026-05-08: 9Technical Details · 2026-05-09: 2Technical Details · 2026-05-10: 1Technical Details · 2026-05-11: 1Technical Details · 2026-05-12: 201-2701-2801-2902-0502-0802-0905-0805-0905-1005-1105-12
Signal classification4 categories
Disclosure
1248.0%
Patch
832.0%
PoC
312.0%
Active Exploitation
28.0%
Referenced assets20 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure1Patch1
2026-01-282
Patch2
2026-01-291
Patch1
2026-02-051
Disclosure1
2026-02-083
Disclosure2Patch1
2026-02-091
Disclosure1
2026-05-089
Active Exploitation2Disclosure6Patch1
2026-05-092
Patch1PoC1
2026-05-101
PoC1
2026-05-111
PoC1
2026-05-122
Disclosure1Patch1
Full discourse20 posts
  • Eugene Kaspersky@e_kaspersky
    Patch

    Our experts have discovered vulnerability CVE-2025-68670 in xrdp, a remote desktop server for Linux using the RDP protocol. A buffer overflow could lead to remote code execution without authentication. The issue has already been fixed in the latest versions. Details: https://kas.pr/8wy6

    Post summary

    The text reports that CVE-2025-68670 is a buffer overflow in xrdp capable of remote code execution, and notes that the flaw has already been fixed in the latest releases.

    3281933810.9K
    178.9K followersView on X
  • Nicolas Krassas@Dinosn
    Disclosure

    CVE-2025-68670: discovering an RCE vulnerability in xrdp https://securelist.com/cve-2025-68670/119742/

    Post summary

    CVE-2025-68670 is a newly discovered RCE vulnerability in xrdp, with no PoC, exploit details, or active exploitation mentioned in the provided text.

    0701672.8K
    158.1K followersView on X
  • Vivek | Cybersecurity@VivekIntel
    Disclosure

    CVE-2025-68670: an RCE vulnerability in the xrdp server | Securelist https://securelist.com/cve-2025-68670/119742/

    Post summary

    The article announces CVE-2025-68670, noting it is an RCE flaw in the xrdp server. No additional details on PoC, exploitation, or patching are provided.

    0201072.0K
    16.1K followersView on X
  • Евгений Касперский@e_kaspersky_ru
    Disclosure

    В xrdp – сервере удалённого рабочего стола по протоколу RDP для Linux – наши эксперты обнаружили уязвимость CVE-2025-68670: переполнение буфера могло привести к удалённому выполнению кода без аутентификации. Проблема уже исправлена в актуальных версиях. Подробности: https://kas.pr/jjh4

    Post summary

    Russian security researchers identified CVE‑2025‑68670 in the xrdp RDP server as a buffer overflow that could allow unauthenticated remote code execution, and note that the issue is already fixed in current releases.

    020311.5K
    24.2K followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    Critical RCE flaw in xrdp remote desktop server allows unauthenticated attackers to execute arbitrary code via crafted UTF-16 domain names that trigger stack buffer overflow. Key technical details: • CVE-2025-68670 (CVSS not specified) affects xrdp versions prior to 0.10.5, 0.9.27, and 0.10.4.1 • Vulnerability in xrdp_wm_parse_domain_information() function processes 512-byte UTF-8 domain into 256-byte buffer • Exploitation occurs during pre-auth Secure Settings Exchange via Client Info PDU (T1210) • Attack vector: domain name starting with "_" followed by >256 UTF-8 bytes before "__" delimiter Attack methodology: • Attacker crafts malicious .rdp file with oversized domain field using UTF-16 to UTF-8 conversion differences • Uses Cyrillic characters (U+041A) to maximize UTF-8 expansion while staying under 512-byte limit • Buffer overflow overwrites stack return address, enabling ROP chain execution • Stack canaries provide partial protection but can be bypassed with value leakage DFIR artifacts: • Monitor for unusual .rdp file creation/modification with abnormally long domain fields • Check xrdp server logs for domain parsing errors or crashes during connection establishment • Examine network traffic for RDP Client Info PDUs with malformed domain strings Patch immediately to fixed versions. Hunt for suspicious .rdp files and correlate xrdp crashes with connection attempts. #DFIR_Radar

    Post summary

    The post announces a critical RCE vulnerability in xrdp enabling stack buffer overflow via crafted UTF‑16 domain names, details the technical mechanism, and urges immediate patching to fixed versions.

    110101.3K
    1.4K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    🚨🚨🚨 『Like the functions described above, this one is called before client authentication, meaning exploitation does not require valid credentials.』 CVE-2025-68670: discovering an RCE vulnerability in xrdp https://securelist.com/cve-2025-68670/119742/

    Post summary

    The post announces a new unauthenticated remote command execution flaw in xrdp, highlighting its technical aspects while lacking PoC or patch details.

    000011.2K
    6.9K followersView on X
  • Mr. OS@ksg93rd
    PoC

    #exploit 1⃣ CVE-2026-31431: Code exec into containers sharing the same image layer https://github.com/sgkdev/page_inject 2⃣ CVE-2025-68670: RCE in the xrdp server https://securelist.com/cve-2025-68670/119742 3⃣ CVE-2026-23918: Apache mod_http2 vulnerability https://github.com/xeloxa/CVE-2026-23918-Apache-H2-PoC // Disclaimer

    Post summary

    The post enumerates several CVEs, providing direct links to Proof‑of‑Concept code and detailed exploitation methods, but it does not report active attacks, patches, or debunking claims.

    000101.1K
    3.3K followersView on X
  • omvapt@omvapt
    PoC

    CVE-2025-68670: an #RCE #vulnerability in the #xrdp_server https://ift.tt/XZoPfLs https://t.co/xBQwEiqAwg

    Post summary

    The tweet announces CVE-2025‑68670 as an RCE in xrdp_server and includes a link that presumably hosts a proof‑of‑concept, but it offers no exploitation tools, evidence of active attacks, or patch information.

    00000969
    383 followersView on X
  • NOCTIS@NoctisIntel
    Patch

    CVE-2025-68670 — xrdp pre-auth RCE Zero creds needed. Port 3389 access = RCE. Chain: xrdp RCE → Dirty Frag (CVE-2026-43284) = remote-to-root OpenCanary: 158,515 RDP hits this week. Patch now. Block 3389 from internet. #ThreatIntel #CVE #RDP #CVE202568670

    Post summary

    CVE-2025-68670 is a pre-auth RCE in xrdp that enables code execution over port 3389 without credentials. A patch is available, and the vulnerability is actively exploited with over 158,000 RDP hits reported by OpenCanary.

    000001.0K
    26 followersView on X
  • Eyal Estrin ☁️@eyalestrin
    PoC

    CVE-2025-68670: discovering an RCE vulnerability in xrdp http://dlvr.it/TSS71D #appsec

    Post summary

    The text announces the discovery of an RCE in xrdp and includes a link that likely points to a proof‑of‑concept, but it does not provide an exploit, patch, or evidence of active exploitation.

    000001.0K
    2.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploiting CVE-2025-68670 to gain unauthenticated RCE on xrdp servers, then escalating privileges and moving laterally through networks. Runtime segmentation helps contain post-compromise activity and limits blast radius. #ZeroDay #CloudSecurity 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/cve-2025-68670-xrdp-remote-code-execution-vulnerability

    Post summary

    CVE-2025-68670 is actively exploited to obtain unauthenticated RCE on xrdp servers, with attackers escalating privileges and moving laterally, but no PoC, exploit code, or patch information is provided.

    000001.0K
    1.9K followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    NEW THREAT INTEL: CVE-2025-68670 - Pre-auth RCE in xrdp <v0.10.5 via Client Info PDU buffer overflow. 9 detections, 18 IOCs. https://intel.threadlinqs.com/#TL-2026-0484 #ThreatIntel #xrdp #RCE https://t.co/HsSnq5jX9X

    Post summary

    Threat intel reports that CVE-2025-68670 delivers a pre‑authentication RCE in xrdp <0.10.5 via a buffer overflow, with nine detections and eighteen IOCs indicating active exploitation, but no PoC, exploit, patch, or false‑positive notes are provided.

    000001.1K
    42 followersView on X
  • ✪ 𝕱𝖆𝖍𝖆𝖉@fad_777
    Disclosure

    اكتشاف ثغرة تنفيذ أوامر عن بعد في xrdp تحت الرمز CVE-2025-68670. Discovering a remote code execution vulnerability in xrdp, identified as CVE-2025-68670. This highlights the importance of regular security audits for open-source software. https://securelist.com/cve-2025-68670/119742/ #CyberSecurity #OpenSource #Vulnerability

    Post summary

    A new CVE-2025-68670 remote code execution vulnerability in xrdp is disclosed, highlighting the importance of security audits; the text does not provide exploitation or patch details.

    000001.1K
    63 followersView on X
  • Shah Sheikh@shah_sheikh
    Patch

    CVE-2025-68670: discovering an RCE vulnerability in xrdp: During a security assessment of Kaspersky USB Redirector, we discovered CVE-2025-68670: a pre-auth RCE in the xrdp server component. Project maintainers promptly patched the vulnerability. https://securelist.com/cve-2025-68670/119742/?utm_source=dlvr.it&utm_medium=twitter https://t.co/RFG0jbJY5k

    Post summary

    The post reports the discovery of the pre‑auth RCE CVE‑2025‑68670 in xrdp and notes that maintainers quickly issued a patch, with no PoC or evidence of active exploitation.

    00000926
    2.3K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Disclosure

    CVE-2025-68670: discovering an RCE vulnerability in xrdp https://securelist.com/cve-2025-68670/119742/?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The tweet announces the discovery of a remote code execution vulnerability (CVE‑2025‑68670) affecting xrdp, with a link to an article for further details.

    000001.4K
    194.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Security Advisory: Critical buffer overflow vulnerability (CVE-2025-68670) identified in xrdp implementation for #SUSE Linux distributions. Read more: 👉 https://tinyurl.com/msykptnz #Security https://t.co/7JOOubdv35

    Post summary

    The advisory announces a critical buffer overflow vulnerability (CVE‑2025‑68670) in the xrdp implementation for SUSE Linux distributions, with a link to further details.

    0000073
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    🚨 Critical Security Alert for Linux Administrators! 🚨 #Fedora 43 systems using xrdp for remote access contain a severe vulnerability (CVE-2025-68670) allowing unauthenticated remote code execution. Read more: 👉 https://tinyurl.com/6r4wwunj #Security https://t.co/2X3RUOR4lL

    Post summary

    The tweet alerts Fedora 43 users to CVE‑2025‑68670, a severe unauthenticated remote code execution flaw in xrdp, but does not provide any PoC, exploit code, active exploitation evidence, or patch details.

    0000062
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    URGENT: Fedora admins - Patch xorgxrdp now! CVE-2025-68670 = critical RCE via stack buffer overflow. Affects xrdp servers on #Fedora 43. Read more: 👉https://tinyurl.com/bhev3hjb #Security https://t.co/DPeRas7ZzL

    Post summary

    Fedora admins are urged to patch xorgxrdp for CVE-2025-68670, a critical RCE caused by a stack buffer overflow affecting Fedora 43.

    0000073
    1.3K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Fedora 43 users warned of critical xrdp bug CVE-2025-68670, a stack-based buffer overflow fixed in xrdp 0.10.5 released Jan 27 2026. Update xrdp and xorgxrdp packages promptly. #LinuxSecurity https://threatcluster.io/cluster/fedora-43-xrdp-vulnerability-cve-2025-68670-affects-multiple-fdee68c9

    Post summary

    Fedora 43 users are warned of a critical stack-based buffer overflow (CVE‑2025‑68670) in xrdp; the issue is fixed in xrdp 0.10.5 (released Jan 27 2026) and users should update the xrdp and xorgxrdp packages immediately.

    0000047
    80 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    Just published: Deep technical analysis of CVE-2025-68670, the critical libpainter0 vulnerability affecting #openSUSE Tumbleweed with CVSS scores reaching 9.2. Read more: 👉 https://tinyurl.com/deb8a8vp #Security https://t.co/ELdaZ8deGK

    Post summary

    A deep technical analysis of CVE-2025-68670, a critical libpainter0 vulnerability with CVSS 9.2 on openSUSE Tumbleweed, has been published, but no PoC, exploit details, patch information, or evidence of active exploitation is provided.

    0000088
    1.3K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux11.0--
Appneutrinolabsxrdp---

Explore more