PT-2026-99119 · Rustdesk · Rustdesk
CVSS v3.1
3.1
Low
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
RustDesk versions prior to 1.5.0
Description
On Windows, the software fails to enforce the one-way file transfer option when handling peer clipboard file requests. This allows authenticated peers to read files from the host clipboard by sending
FormatDataRequest and FileContentsRequest messages and guessing the FileGroupDescriptorW format identifier.Recommendations
Update RustDesk to version 1.5.0 or later.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rustdesk