
🚨High - RustDesk (Windows) clipboard heap buffer overflow via CLIPRDR FileContentsResponse (CVE-2026-76840) CliprdrStream_Read copies with the peer-supplied req_fsize instead of the caller's buffer size, so a malicious peer returning an oversized CB_FILECONTENTS_RESPONSE writes out of bounds when the user pastes remote clipboard files in an OLE consumer. Same root cause as FreeRDP CVE-2026-68579. 👉Affected: RustDesk (Windows) ≤ 1.4.9 | No fixed release — PR #15515. Interim: disable clipboard file transfer
Post summary
An official disclosure of a RustDesk clipboard heap overflow (CVE-2026-76840), including technical details and an interim workaround. No exploitation or PoC evidence is presented.
