RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of RustDesk Client for Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Transfer File feature. By uploading a symbolic link, an attacker can abuse the service to read arbitrary files. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-27909.
History

Fri, 20 Feb 2026 22:45:00 +0000

Type Values Removed Values Added
Description RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of RustDesk Client for Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Transfer File feature. By uploading a symbolic link, an attacker can abuse the service to read arbitrary files. An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. Was ZDI-CAN-27909.
Title RustDesk Client for Windows Transfer File Link Following Information Disclosure Vulnerability
Weaknesses CWE-59
References
Metrics cvssV3_0

{'score': 5.5, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published: 2026-02-20T22:24:43.064Z

Updated: 2026-02-20T22:24:43.064Z

Reserved: 2026-02-13T21:13:34.414Z

Link: CVE-2026-2490

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-20T23:16:05.300

Modified: 2026-02-20T23:16:05.300

Link: CVE-2026-2490

cve-icon Redhat

No data.