← Back

CVE-2025-10539

nvd nist
Published: Apr 28, 2026Modified: Jun 17, 2026

JSON object

Loading...
4.8
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Exploitability: 2.2 / Impact: 2.5
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request. This allows the attacker to achieve user-level remote code execution on the affected client.

Affected (1)

1 product
Desktime Time Tracking
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.3.674

References (5)

Source: 551230f0-3615-47bd-b7cc-93e92e730bbf
Product
Source: 551230f0-3615-47bd-b7cc-93e92e730bbf
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory

Timeline

No history available yet.