MEDIUMVulnerability
Global

CVE-2025-68670: discovering an RCE vulnerability in xrdp

·Source: Securelist (Kaspersky)

Updated:

Executive Summary

During a security assessment of Kaspersky USB Redirector, we discovered CVE-2025-68670: a pre-auth RCE in the xrdp server component. Project maintainers promptly patched the vulnerability.

Analysis

During a security assessment of Kaspersky USB Redirector, we discovered CVE-2025-68670: a pre-auth RCE in the xrdp server component. Project maintainers promptly patched the vulnerability.

Indicators of Compromise (1)

CVE (1)
CVE-2025-68670
Source Attribution

Originally published by Securelist (Kaspersky) on May 8, 2026.

Related Threats