By vendor
Anydesk vulnerabilities
Known CVEs affecting Anydesk products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2016-20094HIGH 7.8
AnyDesk 2.5.0 has a security flaw in how it registers its Windows service. The service path is not properly quoted, which means an attacker with local access to the system can place a malicious program in the system root directory. When AnyDesk starts or the system reboots, Windows will execute the attacker's malicious file instead of the legitimate AnyDesk service, giving it SYSTEM-level privileges—the highest level of access on Windows. This turns a local access vulnerability into a serious privilege escalation problem.