First published: Mon Sep 12 2022(Updated: )
An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is possible if the victim is using the AnyDesk Windows client to connect to a remote machine, if an attacker is also connected remotely with AnyDesk to the same remote machine. The upload is done without any approval or action taken by the victim.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AnyDesk AnyDesk | <6.2.6 | |
AnyDesk AnyDesk | >=6.3.0<6.3.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-44426 is high with a severity value of 8.8.
As a user of the AnyDesk Windows client, an attacker who is connected remotely with AnyDesk can upload an arbitrary file to your local ~/Downloads/ directory.
AnyDesk versions before 6.2.6 and 6.3.x before 6.3.5 are affected by CVE-2021-44426.
To fix CVE-2021-44426, update your AnyDesk Windows client to version 6.2.6 or higher.
You can find more information about CVE-2021-44426 in the references provided: [1](https://anydesk.com/en/downloads/windows) and [2](https://argus-sec.com/discovering-tunneling-service-security-flaws-in-anydesk-remote-application/).