CVE-2021-40854: High severity AnyDesk AnyDesk Windows vulnerability
Published Oct 14, 2021
·Updated
AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that can launch other applications.
Affected Software
2 affected components
AnyDesk AnyDesk Windows>=3.1.0<6.2.6
AnyDesk AnyDesk Windows>6.2.6<=6.3.2
Event History
Oct 14, 2021
CVE Published
via MITRE·04:16 AM
Data Sourced
via MITRE·04:16 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2021-40854?
CVE-2021-40854 is a vulnerability in AnyDesk before versions 6.2.6 and 6.3.x before 6.3.3 that allows a local user to obtain administrator privileges.
2
How can a local user exploit CVE-2021-40854?
A local user can exploit CVE-2021-40854 by using the Open Chat Log feature in AnyDesk to launch a privileged Notepad process that can launch other applications.
3
Which versions of AnyDesk are affected by CVE-2021-40854?
AnyDesk versions before 6.2.6 and 6.3.x before 6.3.3 are affected by CVE-2021-40854.
4
What is the severity of CVE-2021-40854?
CVE-2021-40854 has a severity rating of 7.8 (high).
5
Is there a fix for CVE-2021-40854?
Yes, the fix for CVE-2021-40854 is to update AnyDesk to version 6.2.6 or 6.3.3 or later.