CVE-2024-25140: Critical severity RustDesk RustDesk vulnerability
A default installation of RustDesk 1.2.3 on Windows places a WDKTestCert certificate under Trusted Root Certification Authorities with Enhanced Key Usage of Code Signing (1.3.6.1.5.5.7.3.3), valid from 2023 until 2033. This is potentially unwanted, e.g., because there is no public documentation of security measures for the private key, and arbitrary software could be signed if the private key were to be compromised. NOTE: the vendor's position is "we do not have EV cert, so we use test cert as a workaround." Insertion into Trusted Root Certification Authorities was the originally intended behavior, and the UI ensured that the certificate installation step (checked by default) was visible to the user before proceeding with the product installation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
In the RustDesk Windows installer, disable the default/checked option that installs WDKTestCert into Trusted Root Certification Authorities (the installer UI exposes this certificate installation step before proceeding).
RustDesk (Windows installer) Certificate installation option (checked by default) = unchecked - Compensating control
On affected Windows systems, do not trust arbitrary code-signing test certificates: remove the installed WDKTestCert certificate from the 'Trusted Root Certification Authorities' store (unless required for a specific, documented purpose).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25140?
CVE-2024-25140 is considered a potentially unwanted configuration issue due to the installation of a certificate in the Trusted Root Certification Authorities.
How do I fix CVE-2024-25140?
To mitigate CVE-2024-25140, you should remove the WDKTestCert certificate from the Trusted Root Certification Authorities.
What impact does CVE-2024-25140 have on my system?
CVE-2024-25140 may pose a security risk by allowing unauthorized code to be trusted and executed on your system.
Which software is affected by CVE-2024-25140?
CVE-2024-25140 affects RustDesk version 1.2.3 installed on Windows.
Is there any public documentation regarding CVE-2024-25140?
There is currently no public documentation regarding the WDKTestCert certificate associated with CVE-2024-25140.