The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them to capture any user credentials that are submitted to XRDP and approve or reject arbitrary login credentials. For xorgxrdp sessions in particular, this allows an unauthorized user to hijack an existing session. This is a buffer overflow attack, so there may be a risk of arbitrary code execution as well.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade xrdp | Aug 10, 2020 | Jun 30, 2020 |
| Debian | — | Upgrade xrdp | Jul 31, 2020 | Jun 30, 2020 |
| Freebsd | — | Upgrade xrdp | Jul 1, 2020 | Jun 30, 2020 |
| Suse | — | Upgrade xrdp-develUpgrade librfxencode0Upgrade xrdpUpgrade libpainter0 | Jul 16, 2020 | Jun 30, 2020 |
| Ubuntu | — | Upgrade xrdpUpgrade xrdp (Ubuntu Pro) | Nov 3, 2023 | Jun 30, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub