Kaspersky disclosed CVE-2025-68670, a pre-authentication remote code execution flaw in the open-source xrdp server, after finding the issue during a security audit of Kaspersky USB Redirector. The vulnerability stems from improper handling of the RDP domain field: xrdp converts client-supplied UTF-16 data to UTF-8 and then copies attacker-controlled domain input into a 256-byte stack buffer without sufficient bounds checking, creating a stack-based buffer overflow that can be triggered before authentication.
Kaspersky said it reported the bug to the xrdp maintainers in December 2025, and the project has since released fixes in xrdp 0.10.5 and backported patches to 0.9.27 and 0.10.4.1, alongside a security bulletin. The disclosure notes that while stack canaries may complicate straightforward exploitation, they are not a complete mitigation, and organizations running exposed or internally reachable xrdp services should prioritize upgrading to patched versions.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Kaspersky published a write-up describing CVE-2025-68670 as a pre-authentication RCE in xrdp caused by unsafe conversion and copying of attacker-controlled domain data into a 256-byte stack buffer. The disclosure noted that stack canaries may complicate exploitation but are not a complete mitigation.
The xrdp maintainers fixed CVE-2025-68670 in xrdp 0.10.5, backported the patch to versions 0.9.27 and 0.10.4.1, and published a security bulletin. These updates addressed the pre-authentication buffer overflow vulnerability disclosed by Kaspersky.
Kaspersky discovered CVE-2025-68670, a pre-authentication remote code execution vulnerability in the open-source xrdp server, during a security audit of Kaspersky USB Redirector and reported it to the xrdp maintainers. The flaw stems from improper handling of the RDP domain field, leading to a stack-based buffer overflow before authentication.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.