CVE-2026-100417
Deferred Deferred - Pending Action

RustDesk Windows Clipboard File Read Vulnerability

Vulnerability report for CVE-2026-100417, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-25

Last updated on: 2026-09-25

Assigner: VulnCheck

Description

RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send FormatDataRequest and FileContentsRequest messages to retrieve copied files by guessing the FileGroupDescriptorW format identifier.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-25
Last Modified
2026-09-25
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
rustdesk rustdesk to 1.5.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

RustDesk before version 1.5.0 on Windows has a flaw where the one-way file transfer setting is not enforced against peer clipboard file requests. This allows authenticated peers to read files from the host's clipboard by sending specific messages like FormatDataRequest and FileContentsRequest. Attackers can exploit this by guessing the FileGroupDescriptorW format identifier to retrieve copied files.

Detection Guidance

This vulnerability involves RustDesk's clipboard file transfer feature. To detect it, monitor network traffic for FormatDataRequest and FileContentsRequest messages between RustDesk peers. Check RustDesk logs for unusual file transfer attempts or clipboard interactions. Ensure your RustDesk version is updated to 1.5.0 or later to confirm the fix is applied.

Impact Analysis

If you use RustDesk on Windows before version 1.5.0, an authenticated peer could potentially access files you have copied to your clipboard. This could lead to unauthorized data exposure, including sensitive or confidential files, depending on what you have copied.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, which may violate compliance requirements under GDPR or HIPAA. Organizations using RustDesk before version 1.5.0 on Windows may face increased risk of data breaches, potentially resulting in regulatory penalties or legal consequences.

Mitigation Strategies

Immediately update RustDesk to version 1.5.0 or later to address the clipboard file transfer issue. Disable file transfer capabilities in RustDesk settings if not required. Restrict network access to RustDesk peers to trusted sources only. Monitor clipboard activity for unauthorized file access attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100417. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart