First published: Thu Oct 14 2021(Updated: )
AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that can launch other applications.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AnyDesk AnyDesk | >=3.1.0<6.2.6 | |
AnyDesk AnyDesk | >6.2.6<=6.3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-40854 is a vulnerability in AnyDesk before versions 6.2.6 and 6.3.x before 6.3.3 that allows a local user to obtain administrator privileges.
A local user can exploit CVE-2021-40854 by using the Open Chat Log feature in AnyDesk to launch a privileged Notepad process that can launch other applications.
AnyDesk versions before 6.2.6 and 6.3.x before 6.3.3 are affected by CVE-2021-40854.
CVE-2021-40854 has a severity rating of 7.8 (high).
Yes, the fix for CVE-2021-40854 is to update AnyDesk to version 6.2.6 or 6.3.3 or later.