Possible xrdp RCE Exploitation via ts_info_utf16_in Buffer Overflow (via application)

PremiumReviewedSigma · High · v1
Product
xrdp
Author
HuntRule
Published
2026-10-06
Updated
2026-10-06

ATT&CK techniques

Initial Access → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects xrdp log messages indicating an output buffer overflow in ts_info_utf16_in or a stack smashing abort, artifacts produced when CVE-2025-68670 is exploited through an oversized Client Info PDU domain field. The overflow can lead to remote code execution against the xrdp service. Detecting these log lines surfaces active exploitation of the vulnerable service.

Related detections9 linkedT1190 — drag to rearrange
Zeek HTTP POST to /wsman without Authorization — Possible OMIGOD unauthenticated RCE (CVE-2021-38647)
Windows Terminal Service Parent Process Spawn (svchost.exe termsvcs)
Apache thread assertion error in error.log
Malicious n8n Expression Sandbox Escape child_process Payload
Malicious MOVEit Transfer Exploitation via X-siLock HTTP Headers (via webserver)
Malicious Text4Shell Apache Commons Text Interpolation Payload in HTTP Request
Malicious Child Process Spawned From n8n Node Process
Malicious IIS w3wp Worker Spawning Command Interpreter via SharePoint Web Shell
Suspicious Single-Character Named Executable Launched by Web Server Process (via process_creation)
Possible xrdp RCE Exploitation via ts_info_utf16_in Buffer Overflow (via application)
Pivot detection · T1190 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.