CyberRota Analysis
AI-GeneratedBetterDesk versions up to 2.3.0 are vulnerable due to improper handling of deleted device identities, enabling unauthenticated clients to spoof device IDs and bypass registration controls. This flaw poses a significant risk as it could lead to unauthorized access and control over remote desktop sessions. Organizations using BetterDesk should prioritize upgrading to version 3.0.0-alpha or later to mitigate this high-severity vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an unauthenticated client to replay or spoof a device ID and bypass registration controls. Version 3.0.0-alpha contains a patch. No known workarounds are available.