Impact
RustDesk gates incoming control messages on per‑capability flags and fails to reset them after a file‑transfer session, allowing a peer that has only file‑transfer authorization to inject keyboard and mouse input. This grants the attacker the ability to trigger arbitrary control commands and access screenshot and display‑capture handlers beyond the intended file‑transfer scope, constituting an authorization bypass that can compromise confidentiality, integrity, and availability of the remote system.
Affected Systems
The vulnerability impacts the RustDesk remote‑control application developed by RustDesk. No specific version information is supplied, meaning that all released versions might be affected until a patched release is issued.
Risk and Exploitability
The CVSS score of 7.2 reflects a medium‑to‑high severity risk. With no EPSS score reported and no listing in the CISA KEV catalog, the current exploitation probability is unknown. The likely attack vector is a remote peer authenticating only for file transfer; by exploiting the flag reset flaw, the attacker could inject control commands and capture or manipulate the target’s screen, effectively elevating privileges within the remote session.
OpenCVE Enrichment