← Back

Anydesk

anydesk

16 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Anydesk
anydesk

CVEs (16)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Anydesk
1Anydesk
Feb 25, 2026
Feb 3, 2026
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially inject malicious executables. Attackers can exploit the unquoted binary path t...Show more
AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially inject malicious executables. Attackers can exploit the unquoted binary path to place malicious files in service executable locations, potentially gaining elevated system privileges.Show less
1Anydesk
1Anydesk
Nov 12, 2025
Nov 6, 2025
N/A· v4
8.2 HIGH· v3
N/A· v2
An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing...Show more
An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from the counterparty. Consequently, the attacker can later connect without this counterparty confirmation.Show less
1Anydesk
1Anydesk
Dec 8, 2025
Nov 6, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. It has an integer overflow...Show more
An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. It has an integer overflow and resultant heap-based buffer overflow via a UDP packet during processing of an Identity user image within the Discovery feature, or when establishing a connection between any two clients.Show less
1Anydesk
1Anydesk
Dec 8, 2025
Nov 6, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. Remote Denial of Service ca...Show more
An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL pointer dereference.Show less
1Anydesk
1Anydesk
Dec 8, 2025
Nov 6, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof...Show more
An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof the AnyDesk ID.Show less
1Anydesk
1Anydesk
Aug 14, 2025
Dec 30, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to...Show more
AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of background images. By creating a junction, an attacker can abuse the service to read arbitrary files. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-23940.Show less
1Anydesk
1Anydesk
Nov 21, 2024
Jul 3, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
AnyDesk 7.0.8 allows remote Denial of Service.
1Anydesk
1Anydesk
Nov 21, 2024
Sep 12, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is possible if the victim is using the AnyDesk Windows client to connect t...Show more
An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is possible if the victim is using the AnyDesk Windows client to connect to a remote machine, if an attacker is also connected remotely with AnyDesk to the same remote machine. The upload is done without any approval or action taken by the victim.Show less
1Anydesk
1Anydesk
Nov 21, 2024
Sep 12, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.3. An unnecessarily open listening port on a machine in the LAN of an attacker, opened by the Anydesk Windows client when using the tunneling feature,...Show more
An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.3. An unnecessarily open listening port on a machine in the LAN of an attacker, opened by the Anydesk Windows client when using the tunneling feature, allows the attacker unauthorized access to the local machine's AnyDesk tunneling protocol stack (and also to any remote destination machine software that is listening to the AnyDesk tunneled port).Show less
1Anydesk
1Anydesk
Nov 21, 2024
Jul 18, 2022
N/A· v4
7.1 HIGH· v3
N/A· v2
AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room...Show more
AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.Show less
1Anydesk
1Anydesk
Nov 21, 2024
Oct 14, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that can launch other applications.
1Anydesk
1Anydesk
Nov 21, 2024
Jan 11, 2021
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for...Show more
AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for a Trojan horse gcapi.dll file.Show less
1Anydesk
1Anydesk
Nov 21, 2024
Dec 9, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
AnyDesk for macOS versions 6.0.2 and older have a vulnerability in the XPC interface that does not properly validate client requests and allows local privilege escalation.
1Anydesk
1Anydesk
Nov 21, 2024
Jun 9, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.
1Anydesk
1Anydesk
Nov 21, 2024
Jul 3, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
AnyDesk before "12.06.2018 - 4.1.3" on Windows 7 SP1 has a DLL preloading vulnerability.
1Anydesk
1Anydesk
May 13, 2026
Sep 12, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability.