RustDesk Information Disclosure Vulnerability
A vulnerability in RustDesk allows a remote authenticated attacker to gain unauthorized access to sensitive information.
A security advisory from the BSI reports a vulnerability in the RustDesk remote desktop application that permits an information disclosure. The vulnerability can be exploited by a remote, authenticated attacker to access sensitive information maintained or processed by the application. Because the attacker must already possess authentication credentials to leverage this flaw, the impact is primarily focused on lateral movement, the potential exfiltration of configuration secrets, or unauthorized access to remote session metadata. RustDesk is a cross-platform remote support and desktop software; this vulnerability affects deployments across Windows, Linux, and macOS environments. Organizations utilizing RustDesk should monitor for vendor updates and apply patches once released.
Impact
Successful exploitation results in the unauthorized disclosure of sensitive information managed by the RustDesk application. This could lead to the exposure of connection credentials, session logs, or configuration data, potentially facilitating further unauthorized access or reconnaissance within the host environment. The vulnerability impacts all environments where RustDesk is deployed, including enterprise remote support infrastructure.
Recommendation
Prioritize the identification and inventory of all RustDesk instances across the organization. Monitor the official RustDesk security update channel and apply the security patches immediately upon availability. Given that this vulnerability requires authentication, ensure that robust multi-factor authentication (MFA) is enforced for all RustDesk user accounts to minimize the risk of a malicious actor reaching the authenticated state necessary to exploit this flaw.
Immediate actions
Inventory all RustDesk installations and prepare for version update
Mitigations
Upgrade RustDesk software to the latest secure version once released by the vendor
RustDesk information disclosure vulnerability