Anydesk

Anydesk

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 4.36%
  • Veröffentlicht 30.12.2024 17:15:07
  • Zuletzt bearbeitet 14.08.2025 18:46:10

AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on...

  • EPSS 13.92%
  • Veröffentlicht 18.11.2024 05:15:05
  • Zuletzt bearbeitet 18.11.2024 17:11:17

AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The attacker must know the victim's AnyDesk ID.

  • EPSS 0.22%
  • Veröffentlicht 03.07.2023 15:15:10
  • Zuletzt bearbeitet 21.11.2024 07:51:38

AnyDesk 7.0.8 allows remote Denial of Service.

Exploit
  • EPSS 0.22%
  • Veröffentlicht 12.09.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 06:30:56

An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.3. An unnecessarily open listening port on a machine in the LAN of an attacker, opened by the Anydesk Windows client when using the tunneling feature, allows the attacker unauthoriz...

Exploit
  • EPSS 0.45%
  • Veröffentlicht 12.09.2022 21:15:09
  • Zuletzt bearbeitet 21.11.2024 06:30:56

An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is possible if the victim is using the AnyDesk Windows client to connect to a remote machine, if an atta...

Exploit
  • EPSS 0.12%
  • Veröffentlicht 18.07.2022 13:15:10
  • Zuletzt bearbeitet 21.11.2024 07:06:22

AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.

  • EPSS 0.12%
  • Veröffentlicht 14.10.2021 05:15:07
  • Zuletzt bearbeitet 21.11.2024 06:24:56

AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that can launch other applications.

  • EPSS 0.05%
  • Veröffentlicht 11.01.2021 15:15:13
  • Zuletzt bearbeitet 21.11.2024 05:27:23

AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for a Trojan horse gcapi.dll file...

  • EPSS 0.03%
  • Veröffentlicht 09.12.2020 00:15:13
  • Zuletzt bearbeitet 21.11.2024 05:21:28

AnyDesk for macOS versions 6.0.2 and older have a vulnerability in the XPC interface that does not properly validate client requests and allows local privilege escalation.

Exploit
  • EPSS 77.94%
  • Veröffentlicht 09.06.2020 17:15:10
  • Zuletzt bearbeitet 21.11.2024 05:00:46

AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.