Ghostwire

CVE-2025-10539: Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can...

MEDIUM CVSS 5.5 EPSS 0.02%

Published: April 28, 2026 | Last Modified: April 28, 2026

Description

Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request. This allows the attacker to achieve user-level remote code execution on the affected client.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.02% (4th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (2 articles)

References