Impact
RustDesk versions 1.3.9 through 1.4.9 allow a remote peer to supply file descriptor names during a clipboard file‑paste operation that are joined to the target directory without proper normalization. This enables the attacker to use parent‑directory references or absolute paths to write files outside the intended location, potentially overwriting or creating arbitrary files in directories writable by the RustDesk process. The flaw can thus lead to unauthorized file manipulation and could be leveraged to install malicious files, alter configuration, or expose sensitive data.
Affected Systems
The vulnerability affects RustDesk (rustdesk) software released between versions 1.3.9 and 1.4.9. Users of these specific releases are at risk until a patch is applied.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity issue. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not known to be actively exploited in the wild. The attack requires an active clipboard file‑paste session with a remote peer; the vector is inferred because the description indicates the flaw is triggered during peer‑supplied file descriptor handling. Overall, the risk is moderate; the primary impact is the ability to write files outside the intended directory, which could lead to privilege escalation or compromise if exploited.
OpenCVE Enrichment