Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
RustDesk Missing Session Scope Enforcement Allows Out-of-Scope Control Message Injection
Vulnerability Description
RustDesk before 1.4.9 does not enforce a session's authorized connection scope on the server side, so a peer granted a limited session type (FileTransfer, PortForward, ViewCamera, or Terminal) can send control messages and login options reserved for a full Remote session. An authenticated remote peer can exploit this missing scope check to act outside its granted scope, injecting out-of-scope control messages to observe and control the host beyond the permissions it was given.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Vulnerability Type
授权机制缺失
Vulnerability Title
RustDesk 授权问题漏洞
Vulnerability Description
RustDesk是RustDesk团队开源的一款远程访问和远程控制软件,主要由 Rust 编写,可以远程维护计算机和其他设备。 RustDesk 1.4.9之前版本存在授权问题漏洞,该漏洞源于未强制执行会话的授权连接范围,导致获得有限会话类型(FileTransfer、PortForward、ViewCamera或Terminal)的认证远程对等端可以发送为完整远程会话保留的控制消息和登录选项,从而利用缺失的范围检查在其授权范围之外行动,注入超出范围的控制消息来观察和控制主机。
CVSS Information
N/A
Vulnerability Type
N/A