Vulnerability record · CVE-2022-23478 · published 9 December 2022
CVE-2022-23478: Neutrinolabs xrdp out-of-bounds write vulnerability
NNeutrinolabs · Xrdp
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open() function. There are no known workarounds for this issue. Users are advised to upgrade.
Description
xrdp is an open source project which provides a graphical login to remote machines using Microsoft Remote Desktop Protocol (RDP). xrdp < v0.9.21 contain a Out of Bound Write in xrdp_mm_trans_process_drdynvc_channel_open() function. There are no known workarounds for this issue. Users are advised to upgrade.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-2f49-wwpm-78pj | Third Party Advisory |
| https://www.debian.org/security/2023/dsa-5502 | Third Party Advisory |
| https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-2f49-wwpm-78pj | Third Party Advisory |
| https://www.debian.org/security/2023/dsa-5502 | Third Party Advisory |
Track CVE-2022-23478 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-23478), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.