Improper Certificate Validation vulnerability in rustdesk-client RustDesk Client rustdesk-client on Windows, MacOS, Linux, iOS, Android (HTTP API client, TLS transport modules) allows Adversary in the Middle (AiTM). This vulnerability is associated with program files src/hbbs_http/http_client.Rs and program routines TLS retry with danger_accept_invalid_certs(true).
This issue affects RustDesk Client: through 1.4.5.
Default — any client connecting to API server via HTTPS
PoC available. Trivially exploitable.
Ensure network path to API server cannot be intercepted (VPN, direct link)
Remove automatic fallback. Treat TLS handshake failures as fatal.