---
schema: 1
kind: vulnerability
title: "CVE-2025-68670 — xrdp pre-authentication stack overflow, arbitrary code execution"
headline: "CVE-2025-68670 — xrdp pre-authentication stack overflow, arbitrary code execution"
summary: "CVE-2025-68670 is a pre-authentication stack buffer overflow in the xrdp_wm_parse_domain_information function of xrdp (open-source RDP server for Linux), disclosed by Kaspersky researchers Denis Skvortsov and Dmitry Shmoylov on 2026-05-08."
discovered_at: "2026-05-09T05:00:07Z"
event_date: 2026-05-08
run_id: 2026-05-09-migrated
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - pre-auth
  - rce
  - patch-available
regions:
  - global
sectors: []
entities: []
cves:
  - id: CVE-2025-68670
    cvss: n/a
    epss: null
    type: rce
    vector: zero-click
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://securelist.com/cve-2025-68670/119742/"
    publisher: "Kaspersky Securelist — CVE-2025-68670, 2026-05-08"
    role: primary
closed_sources: []
evidence: []
verification: single-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "Patch to **xrdp 0.10.5** (or backport packages for 0.10.4.1 / 0.9.27 per your distribution)."
  - "If Linux RDP endpoints are internet-accessible, restrict to VPN-only access. RDP on internet-facing Linux hosts is an unnecessary attack surface in virtually all enterprise configurations."
migrated_from: briefs/2026-05-09.md
---

CVE-2025-68670 is a pre-authentication stack buffer overflow in the `xrdp_wm_parse_domain_information` function of xrdp (open-source RDP server for Linux), disclosed by Kaspersky researchers Denis Skvortsov and Dmitry Shmoylov on 2026-05-08. Domain names beginning with an underscore and containing `__` delimiters are processed via a UTF-16-to-UTF-8 conversion path and written from a 512-byte input buffer into a 256-byte stack buffer without bounds checking; the conversion step amplifies the overflow size. Stack canaries are present but bypassable via canary leakage. The vulnerability was reported 2025-12-05, CVE assigned 2025-12-24, mainline patch merged 2026-01-27; public disclosure followed on 2026-05-08. Affects xrdp < 0.10.5; backports available for 0.9.27 and 0.10.4.1 ([Kaspersky Securelist — CVE-2025-68670, 2026-05-08](https://securelist.com/cve-2025-68670/119742/)). xrdp is widely deployed in Linux remote-access and thin-client environments, including public-sector Linux desktops.


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-42208 | LiteLLM Proxy | 9.3 | n/a | Yes (due 2026-05-11) | Yes — ITW ~26 h post-advisory | v1.83.7+ | [Bishop Fox](https://bishopfox.com/blog/cve-2026-42208-pre-authentication-sql-injection-in-litellm-proxy) |
| CVE-2026-43284 | Linux kernel (xfrm-ESP) | n/a | n/a | No | Yes — limited campaigns (Microsoft) | Mainline patch 2026-05-08; distro updates in progress | [Wiz Research](https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc) |
| CVE-2026-43500 | Linux kernel (RxRPC) | n/a | n/a | No | Yes — limited campaigns (Microsoft) | Kernel patch PENDING; distro patches PENDING | [Wiz Research](https://www.wiz.io/blog/dirty-frag-linux-kernel-local-privilege-escalation-via-esp-and-rxrpc) |
| CVE-2026-44128 | SEPPmail Secure Email Gateway | 9.3 | n/a | No | None confirmed | patch 15.0.4.1 | [NCSC-CH 12551](https://security-hub.ncsc.admin.ch/api/posts/12551/details) |
| CVE-2026-44125 | SEPPmail (GINAv2) | 9.3 | n/a | No | None confirmed | patch 15.0.4 | [NCSC-CH 12551](https://security-hub.ncsc.admin.ch/api/posts/12551/details) |
| CVE-2026-44126 | SEPPmail | 9.2 | n/a | No | None confirmed | patch 15.0.4 | [NCSC-CH 12551](https://security-hub.ncsc.admin.ch/api/posts/12551/details) |
| CVE-2026-40982 | Spring Cloud Config Server | 9.8 | n/a | No | None confirmed | 4.3.3 / 5.0.3 (OSS) | [Spring.io](https://spring.io/security/cve-2026-40982) |
| CVE-2025-68670 | xrdp | n/a | n/a | No | None confirmed | xrdp 0.10.5 / 0.10.4.1 / 0.9.27 | [Kaspersky Securelist](https://securelist.com/cve-2025-68670/119742/) |
