An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is possible if the victim is using the AnyDesk Windows client to connect to a remote machine, if an attacker is also connected remotely with AnyDesk to the same remote machine. The upload is done without any approval or action taken by the victim.
References
Link | Resource |
---|---|
https://anydesk.com/en/downloads/windows | Product Vendor Advisory |
https://argus-sec.com/discovering-tunneling-service-security-flaws-in-anydesk-remote-application/ | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-09-12 14:15
Updated : 2022-09-16 08:09
NVD link : CVE-2021-44426
Mitre link : CVE-2021-44426
JSON object : View
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
Products Affected
anydesk
- anydesk