xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The `auth_start_session` function can return non-zero (1) value on, e.g., PAM error which may result in in session restrictions such as max concurrent sessions per user by PAM (ex ./etc/security/limits.conf) to be bypassed. Users (administrators) don't use restrictions by PAM are not affected. This issue has been addressed in release version 0.9.23. Users are advised to upgrade. There are no known workarounds for this issue.
CVSS Details
- CVSS 3.1 Base Score: 2.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xrdp | Aug 22, 2024 | Aug 30, 2023 |
| Debian | — | Upgrade xrdp | May 15, 2025 | Aug 30, 2023 |
| Freebsd | — | Upgrade xrdp | Sep 28, 2023 | Sep 27, 2023 |
| Suse | — | Upgrade xrdpUpgrade librfxencode0Upgrade libpainter0Upgrade xrdp-devel | Sep 25, 2023 | Aug 30, 2023 |
| Ubuntu | — | Upgrade xrdp (Ubuntu Pro) | Nov 13, 2023 | Aug 30, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub