First published: Mon Jan 11 2021(Updated: )
AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for a Trojan horse gcapi.dll file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AnyDesk AnyDesk | >=5.4.2<6.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-35483 is a vulnerability in AnyDesk before version 6.1.0 on Windows that allows an attacker with write access to the application directory to compromise a local user account.
CVE-2020-35483 affects AnyDesk before version 6.1.0 on Windows when run in portable mode.
The severity of CVE-2020-35483 is high, with a CVSS score of 7.8.
An attacker can exploit CVE-2020-35483 by adding a Trojan horse gcapi.dll file with read-only setting to the AnyDesk application directory.
To fix CVE-2020-35483, update AnyDesk to version 6.1.0 or later.