CVE-2026-100417
RustDesk before 1.5.0 One-Way File Transfer Bypass
CVSS Score
3.1
EPSS Score
0.0%
EPSS Percentile
0th
RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send FormatDataRequest and FileContentsRequest messages to retrieve copied files by guessing the FileGroupDescriptorW format identifier.
| CWE | CWE-862 |
| Vendor | rustdesk |
| Product | rustdesk |
| Published | Sep 25, 2026 |
Stay Ahead of the Next One
Get instant alerts for rustdesk rustdesk
Be the first to know when new low vulnerabilities affecting rustdesk rustdesk are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
rustdesk / rustdesk
0 < 1.5.0
References
github.com: https://github.com/rustdesk/rustdesk/pull/16333 github.com: https://github.com/rustdesk/rustdesk/commit/f299fb9906006247863250d7dfaa016f29eef7a4 github.com: https://github.com/rustdesk/rustdesk/blob/1.4.9/src/ui_cm_interface.rs#L618-L638 github.com: https://github.com/rustdesk/rustdesk/blob/1.4.9/libs/clipboard/src/windows/wf_cliprdr.c#L2728-L2770 github.com: https://github.com/rustdesk/rustdesk vulncheck.com: https://www.vulncheck.com/advisories/rustdesk-before-1.5.0-one-way-file-transfer-bypass
Credits
RustDesk