PT-2026-35686 · Desktime · Desktime Time Tracking App
Published
2026-04-28
·
Updated
2026-05-18
·
CVE-2025-10539
CVSS v3.1
4.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
DeskTime Time Tracking App versions prior to 1.3.674
Description
Improper TLS certificate validation allows attackers positioned in the network path between the client and the update servers to return a malicious executable during an update request. This can lead to user-level remote code execution on the affected client.
Recommendations
Update to version 1.3.674 or later.
Exploit
Fix
RCE
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Desktime Time Tracking App