Impact
RustDesk before version 1.4.9 lets an authenticated peer bypass the server‑side check of a session’s authorized scope. Because the server does not enforce the predefined session type (FileTransfer, PortForward, ViewCamera or Terminal), the remote client can send control messages and login options normally reserved for a full Remote session. This missing authorization control (CWE‑862) enables the attacker to observe and control the host beyond the permissions it was granted, compromising confidentiality, integrity, and availability.
Affected Systems
The affected product is RustDesk. Any installation of RustDesk earlier than reference version 1.4.9 is vulnerable, regardless of the platform. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 8.7 denotes high severity, while the EPSS score of less than 1 percent indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated remote connection that has been granted a limited session type; from that position, crafted control messages can bypass the server‑side scope check and extend the remote peer’s activity beyond the intended session, allowing unauthorized control of the host.
OpenCVE Enrichment