Skip to main content

Missing TLS Certificate Validation leading to RCE in DeskTime Time Tracking App

A flawed TLS server certificate validation in DeskTime’s “DeskTime Time Tracker” application enabled attackers, who can inject themselves into the network path between the client and the server, to execute arbitrary code with user privileges. The vendor did not provide a patch nor a timeline when a fix will be available.
CVE-2025-10539

Read the full advisory here

Share this article

Dive deeper

  • Service Focus

Cybersecurity

  • Magazine

Digital security magazine 17

  • Magazine

Digital security magazine 18th Edition