Missing TLS Certificate Validation leading to RCE in DeskTime Time Tracking App
A flawed TLS server certificate validation in DeskTime’s “DeskTime Time Tracker” application enabled attackers, who can inject themselves into the network path between the client and the server, to execute arbitrary code with user privileges. The vendor did not provide a patch nor a timeline when a fix will be available.
CVE-2025-10539


