Description
RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send FormatDataRequest and FileContentsRequest messages to retrieve copied files by guessing the FileGroupDescriptorW format identifier.
Published: 2026-09-25
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 00:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 25 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
Description RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send FormatDataRequest and FileContentsRequest messages to retrieve copied files by guessing the FileGroupDescriptorW format identifier.
Title RustDesk before 1.5.0 One-Way File Transfer Bypass
First Time appeared Rustdesk
Rustdesk rustdesk
Weaknesses CWE-862
CPEs cpe:2.3:a:rustdesk:rustdesk:*:*:*:*:*:*:*:*
Vendors & Products Rustdesk
Rustdesk rustdesk
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Rustdesk Rustdesk
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-30T00:09:30.175Z

Reserved: 2026-09-25T20:19:11.490Z

Link: CVE-2026-100417

cve-icon Vulnrichment

Updated: 2026-09-30T00:09:25.759Z

cve-icon NVD

Status : Deferred

Published: 2026-09-25T21:17:22.957

Modified: 2026-09-30T01:16:32.313

Link: CVE-2026-100417

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T10:45:11Z

Weaknesses