Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-58056

Опубликовано: 28 июн. 2026
Источник: nvd
CVSS3: 7.6
EPSS Низкий

Описание

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboard and mouse input and reach the unguarded screenshot and display-capture handlers, acting outside its granted scope.

EPSS

Процентиль: 25%
0.00326
Низкий

7.6 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 7.6
github
2 месяца назад

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer authorization can inject keyboard and mouse input and reach the unguarded screenshot and display-capture handlers, acting outside its granted scope.

EPSS

Процентиль: 25%
0.00326
Низкий

7.6 High

CVSS3

Дефекты

CWE-863