CVE-2021-44426: Malicious File Upload
An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is possible if the victim is using the AnyDesk Windows client to connect to a remote machine, if an attacker is also connected remotely with AnyDesk to the same remote machine. The upload is done without any approval or action taken by the victim.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44426?
The severity of CVE-2021-44426 is high with a severity value of 8.8.
How can I exploit CVE-2021-44426?
As a user of the AnyDesk Windows client, an attacker who is connected remotely with AnyDesk can upload an arbitrary file to your local ~/Downloads/ directory.
Which versions of AnyDesk are affected by CVE-2021-44426?
AnyDesk versions before 6.2.6 and 6.3.x before 6.3.5 are affected by CVE-2021-44426.
How do I fix CVE-2021-44426?
To fix CVE-2021-44426, update your AnyDesk Windows client to version 6.2.6 or higher.
Where can I find more information about CVE-2021-44426?
You can find more information about CVE-2021-44426 in the references provided: [1](https://anydesk.com/en/downloads/windows) and [2](https://argus-sec.com/discovering-tunneling-service-security-flaws-in-anydesk-remote-application/).