Rustdesk
Rustdesk: vulnerabilidades y CVE
Rustdesk tiene 17 vulnerabilidades publicadas, 16 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses16
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-100417 | Baja (2.3) | 0.21% | — | 25 sept 2026 | RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send… |
| CVE-2026-100388 | Media (5.3) | 0.18% | — | 25 sept 2026 | RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages in the Cliprdr message handler on Linux and macOS. Authenticated remote peers with disabled file… |
| CVE-2026-73108 | Alta (8.7) | 0.77% | — | 26 ago 2026 | RustDesk versions before 1.4.7 contain an uncontrolled speculative memory allocation vulnerability in BytesCodec. Before authentication, the decoder trusts the payload length encoded in a four-byte frame header and… |
| CVE-2026-73102 | Media (6.9) | 0.39% | — | 26 ago 2026 | RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnerability in the macOS clipboard file-paste code path. The application accepts peer-supplied file descriptor names and joins them to the selected target… |
| CVE-2026-76840 | Alta (8.5) | 0.43% | — | 24 ago 2026 | RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Read with a buffer of… |
| CVE-2026-57850 | Alta (8.7) | 0.50% | — | 10 jul 2026 | RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages… |
| CVE-2026-58056 | Alta (7.2) | 0.33% | — | 28 jun 2026 | RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer… |
| CVE-2026-30798 | Alta (8.2) | 0.33% | — | 5 mar 2026 | Insufficient Verification of Data Authenticity, Improper Handling of Exceptional Conditions vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop,… |
| CVE-2026-30797 | Crítica (9.3) | 0.56% | — | 5 mar 2026 | Missing Authorization vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, config import modules) allows Application API Message… |
| CVE-2026-30795 | Alta (8.7) | 0.32% | — | 5 mar 2026 | Cleartext Transmission of Sensitive Information vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Heartbeat sync loop modules) allows Sniffing Attacks. This… |
| CVE-2026-30793 | Crítica (9.3) | 0.34% | — | 5 mar 2026 | Cross-Site Request Forgery (CSRF) vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (Flutter URI scheme handler, FFI bridge modules) allows Privilege Escalation.… |
| CVE-2026-30792 | Alta (8.3) | 0.29% | — | 5 mar 2026 | A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Strategy sync, HTTP API client, config options engine modules) allows Application API Message… |
| CVE-2026-30789 | Media (5.7) | 0.33% | — | 5 mar 2026 | Use of Password Hash With Insufficient Computational Effort, Improper Restriction of Excessive Authentication Attempts vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS,… |
| CVE-2026-30785 | Alta (8.2) | 0.14% | — | 5 mar 2026 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'), Use of Password Hash With Insufficient Computational Effort vulnerability in rustdesk-client RustDesk Client rustdesk,… |
| CVE-2026-30783 | Media (4.8) | 0.46% | — | 5 mar 2026 | A vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Client signaling, API sync loop, config management modules) allows Privilege Abuse. This… |
| CVE-2026-30791 | Alta (8.7) | 0.33% | — | 5 mar 2026 | Use of a Broken or Risky Cryptographic Algorithm vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android, WebClient (Config import, URI scheme handler, CLI --config… |
| CVE-2024-25140 | Crítica (9.8) | 0.51% | — | 6 feb 2024 | A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key Usage of Code Signing (1.3.6.1.5.5.7.3.3), valid from 2023 until 2033.… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.