PT-2026-99108 · Rustdesk · Rustdesk
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
RustDesk versions prior to 1.5.0
Description
On Linux and macOS, the
Cliprdr message handler fails to properly validate file transfer permissions for incoming file clipboard messages. This allows authenticated remote peers, even those with file transfer permissions disabled, to place files onto the host clipboard and retrieve copied files and contents from the process-wide clipboard cache.Recommendations
Update to version 1.5.0 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rustdesk