CVE-2026-100417 Details
Description
RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send FormatDataRequest and FileContentsRequest messages to retrieve copied files by guessing the FileGroupDescriptorW format identifier.
A vulnerability in RustDesk versions prior to 1.5.0 on Windows allows authenticated peers to bypass the one-way file transfer restriction. This flaw enables them to access files from the host's clipboard during a remote session. The issue arises because the application does not properly enforce file transfer permissions on incoming requests from peers. Exploitation involves sending specific messages to request clipboard files, which are then delivered without the necessary authorization checks.
Users can upgrade to RustDesk version 1.5.0 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 25, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| RustDesk | >= 0, < 1.5.0 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 25, 2026 | New CVE Received | [email protected] |
Volerion