An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is possible if the victim is using the AnyDesk Windows client to connect to a remote machine, if an attacker is also connected remotely with AnyDesk to the same remote machine. The upload is done without any approval or action taken by the victim.
References
Link | Resource |
---|---|
https://anydesk.com/en/downloads/windows | Product Vendor Advisory |
https://argus-sec.com/discovering-tunneling-service-security-flaws-in-anydesk-remote-application/ | Exploit Third Party Advisory |
https://anydesk.com/en/downloads/windows | Product Vendor Advisory |
https://argus-sec.com/discovering-tunneling-service-security-flaws-in-anydesk-remote-application/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:30
Type | Values Removed | Values Added |
---|---|---|
References | () https://anydesk.com/en/downloads/windows - Product, Vendor Advisory | |
References | () https://argus-sec.com/discovering-tunneling-service-security-flaws-in-anydesk-remote-application/ - Exploit, Third Party Advisory |
16 Sep 2022, 15:09
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://argus-sec.com/discovering-tunneling-service-security-flaws-in-anydesk-remote-application/ - Exploit, Third Party Advisory | |
References | (MISC) https://anydesk.com/en/downloads/windows - Product, Vendor Advisory | |
CPE | cpe:2.3:a:anydesk:anydesk:*:*:*:*:*:windows:*:* | |
CWE | CWE-434 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
12 Sep 2022, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-09-12 21:15
Updated : 2024-11-21 06:30
NVD link : CVE-2021-44426
Mitre link : CVE-2021-44426
CVE.ORG link : CVE-2021-44426
JSON object : View
Products Affected
anydesk
- anydesk
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type