ID:12570 - Exploit for Download of code without integrity check in TrueConf client for Windows - CVE-2026-3502

 
Main Vulnerability Database Exploits ID:12570 - Exploit for Download of code without integrity check in TrueConf client for Windows - CVE-2026-3502

ID:12570 - Exploit for Download of code without integrity check in TrueConf client for Windows - CVE-2026-3502

Published: April 10, 2026


Vulnerability identifier: #VU124719
Vulnerability risk: Critical
CVE-ID: CVE-2026-3502
CWE-ID: CWE-494
Exploitation vector: Remote access
Vulnerable software:
TrueConf client for Windows

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to compromise the affected system

The vulnerability exists due to software does not perform software integrity check when downloading updates. A remote attacker controlling a TrueConf server can supply a malicious software binary and gain full control over the affected system after a successful software update.

Note, the vulnerability is being exploited in the wild. 


Remediation

Install updates from vendor's website.