CyberRota Analysis
AI-GeneratedRustDesk versions prior to 1.4.9 are vulnerable due to a lack of enforcement on session authorization, allowing authenticated peers with limited session types to send unauthorized control messages. This oversight can lead to unauthorized access and control over the host system, significantly compromising security. Organizations using RustDesk should prioritize patching to mitigate the risk of exploitation.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options reserved for a full Remote session. An authenticated remote peer can exploit this missing scope check to act outside its granted scope, injecting out-of-scope control messages to observe and control the host beyond the permissions it was given.