---
id: CVE-2026-100417
title: >-
  RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer
  option against peer clipboard file requests, allowing authenticated peers to
  read files from the host clipboard
summary: >-
  RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer
  option against peer clipboard file requests, allowing authenticated peers to
  read files from the host clipboard. Attackers can send FormatDataRequest and
  FileCon…
severity: low
cvss: 3.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-862
vendor: rustdesk
product: rustdesk
affected:
  - rustdesk < 1.5.0
published: '2026-09-25'
updated: '2026-09-25'
sourceUpdated: '2026-09-25T21:17:23.080'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-100417'
references:
  - url: 'https://github.com/rustdesk/rustdesk'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/rustdesk/rustdesk/blob/1.4.9/libs/clipboard/src/windows/wf_cliprdr.c#L2728-L2770
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/rustdesk/rustdesk/blob/1.4.9/src/ui_cm_interface.rs#L618-L638
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/rustdesk/rustdesk/commit/f299fb9906006247863250d7dfaa016f29eef7a4
    label: disclosure@vulncheck.com
  - url: 'https://github.com/rustdesk/rustdesk/pull/16333'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/rustdesk-before-1.5.0-one-way-file-transfer-bypass
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-25T21:19:40.143Z'
epss: 0.00208
epssPercentile: 0.09752
---

## Overview

RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests, allowing authenticated peers to read files from the host clipboard. Attackers can send FormatDataRequest and FileContentsRequest messages to retrieve copied files by guessing the FileGroupDescriptorW format identifier.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
