CVE-2026-100417: RustDesk before 1.5.0 One-Way File Transfer Bypass
RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send FormatDataRequest and FileContentsRequest messages to retrieve copied files by guessing the FileGroupDescriptorW format identifier.
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed?
Windows systems running RustDesk before 1.5.0 are affected when the one-way file transfer option is enabled and files have been copied to the host clipboard.
What does an attacker need to exploit this?
The attacker must be an authenticated RustDesk peer. They can request clipboard file data using FormatDataRequest and FileContentsRequest messages after guessing the FileGroupDescriptorW format identifier.
Does enabling one-way file transfer prevent this disclosure?
No. On affected Windows versions, one-way file transfer is not enforced for peer clipboard file requests, so it does not prevent an authenticated peer from reading copied files from the host clipboard.
How can I tell whether data may be exposed?
Exposure is possible if RustDesk before 1.5.0 was used on Windows with one-way file transfer enabled, an authenticated peer was connected, and files were copied to the host clipboard during that connection.