CVE-2020-4044 HIGH

CVE-2020-4044: Local users can perform a buffer overflow attack against the xrdp-sesman service and then impersonate it

Vendor Neutrinolabs
Product xrdp
Weakness CWE-121
Published June 30, 2020
Last update August 4, 2024

CVSS base score

7.5/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

What the vulnerability does

01Description

The xrdp-sesman service before version 0.9.13.1 can be crashed by connecting over port 3350 and supplying a malicious payload. Once the xrdp-sesman process is dead, an unprivileged attacker on the server could then proceed to start their own imposter sesman service listening on port 3350. This will allow them to capture any user credentials that are submitted to XRDP and approve or reject arbitrary login credentials. For xorgxrdp sessions in particular, this allows an unauthorized user to hijack an existing session. This is a buffer overflow attack, so there may be a risk of arbitrary code execution as well.

Key dates

02Disclosure timeline

June 30, 2020 CVE published
August 4, 2024 Record updated

Related vulnerabilities

04Related CVE