By vendor

Anydesk vulnerabilities

Known CVEs affecting Anydesk products, prioritized by severity, with SEC.co remediation and detection guidance.

1 published vulnerability

  • CVE-2016-20094HIGH 7.8

    AnyDesk 2.5.0 has a security flaw in how it registers its Windows service. The service path is not properly quoted, which means an attacker with local access to the system can place a malicious program in the system root directory. When AnyDesk starts or the system reboots, Windows will execute the attacker's malicious file instead of the legitimate AnyDesk service, giving it SYSTEM-level privileges—the highest level of access on Windows. This turns a local access vulnerability into a serious privilege escalation problem.