Rustdesk

Rustdesk

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.21%
  • Veröffentlicht 25.09.2026 20:25:18
  • Zuletzt bearbeitet 30.09.2026 01:16:32

RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send FormatDataRequest and FileContentsRequest ...

  • EPSS 0.18%
  • Veröffentlicht 25.09.2026 20:13:06
  • Zuletzt bearbeitet 30.09.2026 01:16:32

RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authenticated remote peers with disabled file transfer permissions can place fil...

  • EPSS 0.53%
  • Veröffentlicht 26.08.2026 13:00:29
  • Zuletzt bearbeitet 23.09.2026 17:17:45

RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and reserves that amount before receivi...

  • EPSS 0.29%
  • Veröffentlicht 26.08.2026 13:00:00
  • Zuletzt bearbeitet 23.09.2026 17:17:43

RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path. The application accepts peer-supplied file descriptor names and joins them to the selected target directory without requiring no...

  • EPSS 0.3%
  • Veröffentlicht 24.08.2026 13:11:58
  • Zuletzt bearbeitet 23.09.2026 17:17:42

RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Read with a buffer of cb bytes, CliprdrStream_Read in ...

  • EPSS 0.42%
  • Veröffentlicht 10.07.2026 19:53:21
  • Zuletzt bearbeitet 11.08.2026 14:17:14

RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options reserved for ...

  • EPSS 0.19%
  • Veröffentlicht 28.06.2026 02:16:32
  • Zuletzt bearbeitet 18.07.2026 21:17:03

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboa...

Exploit
  • EPSS 0.08%
  • Veröffentlicht 05.03.2026 16:16:19
  • Zuletzt bearbeitet 25.03.2026 15:47:08

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk, hbb_common on Windows, MacOS, Linux (Pas...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 05.03.2026 16:16:18
  • Zuletzt bearbeitet 22.06.2026 14:16:35

A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This vulnerability is associated with program ...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 05.03.2026 15:41:51
  • Zuletzt bearbeitet 22.06.2026 14:16:36

Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Client login, peer authent...