CVE-2016-20094: AnyDesk 2.5.0 Unquoted Service Path Elevation of Privilege
AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers can insert malicious executables in the system root path that execute with elevated privileges during application startup or system reboot.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AnyDeskto a version that resolves this vulnerability.Fixed in 2.5.0 - Compensating control
Mitigate the unquoted service path elevation of privilege by preventing local users from being able to place malicious executables in the system root path used by the AnyDesk service during startup/reboot (restrict write/modify permissions to that path for non-admin users).
Event History
Frequently Asked Questions
What is the severity of CVE-2016-20094?
The severity of CVE-2016-20094 is high with a score of 8.5.
How do I fix CVE-2016-20094?
To fix CVE-2016-20094, ensure that the service path is properly quoted to prevent unquoted service path exploitation.
What type of vulnerability is CVE-2016-20094?
CVE-2016-20094 is an unquoted service path vulnerability that allows for elevation of privilege.
What can attackers do by exploiting CVE-2016-20094?
Attackers can execute arbitrary code with SYSTEM privileges by exploiting the unquoted service path in AnyDesk 2.5.0.
Which version of AnyDesk is affected by CVE-2016-20094?
CVE-2016-20094 specifically affects AnyDesk version 2.5.0.