Impact
Rocket Software Rocket Remote Desktop version 18.0.8583.1 contains insufficiently protected credentials, meaning user login information may be stored or transmitted without adequate safeguards. This weakness allows an attacker who obtains or guesses valid credentials to gain unauthorized access, potentially escalating to system control and exposing sensitive data. The impact is primarily the loss of confidentiality and integrity for users and any information accessed through the remote desktop session.
Affected Systems
The affected vendor is Rocket Software, with the product Rocket Remote Desktop. The vulnerability applies to the 18.0.8583.1 build; other releases are not confirmed as vulnerable.
Risk and Exploitability
The CVSS score is not published, and the EPSS indicates no data, so exact exploitation probability cannot be quantified. The vulnerability is not listed in CISA KEV. Attackers could remotely target the authentication mechanism, infer or brute‑force credentials, and then log into the remote desktop service. No known work‑arounds are provided by the vendor, so the primary risk is exploitation of exposed plaintext or weakly encrypted credentials.
OpenCVE Enrichment