Vulnerabilities (CVE)

Filtered by vendor Anydesk Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-32450 1 Anydesk 1 Anydesk 2022-07-22 N/A 7.1 HIGH
AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.
CVE-2021-40854 1 Anydesk 1 Anydesk 2021-10-20 4.6 MEDIUM 7.8 HIGH
AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that can launch other applications.
CVE-2020-27614 1 Anydesk 1 Anydesk 2021-07-21 7.2 HIGH 7.8 HIGH
AnyDesk for macOS versions 6.0.2 and older have a vulnerability in the XPC interface that does not properly validate client requests and allows local privilege escalation.
CVE-2020-35483 1 Anydesk 1 Anydesk 2021-01-20 4.4 MEDIUM 7.8 HIGH
AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for a Trojan horse gcapi.dll file.
CVE-2018-13102 2 Anydesk, Microsoft 2 Anydesk, Windows 7 2018-09-11 6.8 MEDIUM 7.8 HIGH
AnyDesk before "12.06.2018 - 4.1.3" on Windows 7 SP1 has a DLL preloading vulnerability.