CVE-2026-76840Disclosure

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

RustDesk's Windows clipboard redirection copies a peer-supplied length into a fixed-size caller buffer without an upper bound check. When an OLE paste consumer such as explorer.exe calls IStream::Read with a buffer of cb bytes, CliprdrStream_Read in libs/clipboard/src/windows/wf_cliprdr.c requests that many bytes of a remote file through cliprdr_send_request_filecontents and then executes CopyMemory(pv, clipboard->req_fdata, clipboard->req_fsize), where req_fsize is taken verbatim from the peer's CLIPRDR FileContentsResponse by wf_cliprdr_server_file_contents_response (req_fsize = fileContentsResponse->cbRequested) and is never clamped to cb anywhere in the chain. The function's only length comparison, req_fsize < cb, handles the short-read case and is evaluated after the copy has already occurred. A malicious or compromised peer that answers a small file-contents read with an oversized response therefore writes attacker-chosen data past the end of the paste consumer's heap buffer when the local user pastes clipboard file contents offered by the remote side. The file is a fork of FreeRDP's client/Windows/wf_cliprdr.c, where the same defect is CVE-2026-68579, fixed in FreeRDP 3.30.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-25: 1Patch / Workaround · 2026-08-25: 1Technical Details · 2026-08-25: 108-25
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - RustDesk (Windows) clipboard heap buffer overflow via CLIPRDR FileContentsResponse (CVE-2026-76840) CliprdrStream_Read copies with the peer-supplied req_fsize instead of the caller's buffer size, so a malicious peer returning an oversized CB_FILECONTENTS_RESPONSE writes out of bounds when the user pastes remote clipboard files in an OLE consumer. Same root cause as FreeRDP CVE-2026-68579. 👉Affected: RustDesk (Windows) ≤ 1.4.9 | No fixed release — PR #15515. Interim: disable clipboard file transfer

    Post summary

    An official disclosure of a RustDesk clipboard heap overflow (CVE-2026-76840), including technical details and an interim workaround. No exploitation or PoC evidence is presented.

    0000081
    294 followersView on X

Explore more