CVE-2024-52940: High severity anydesk vulnerability
Published Nov 18, 2024
·Updated
AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The attacker must know the victim's AnyDesk ID.
Affected Software
2 affected components
AnyDesk AnyDesk<=8.1.0
Microsoft Windows
Event History
Nov 18, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-52940?
CVE-2024-52940 is classified as a medium-severity vulnerability due to the potential exposure of a user's public IP address.
2
How do I fix CVE-2024-52940?
To mitigate CVE-2024-52940, users should disable the Allow Direct Connections feature in AnyDesk settings.
3
What impact does CVE-2024-52940 have on users?
CVE-2024-52940 can lead to the unintentional exposure of a user's public IP address, increasing the risk of targeted attacks.
4
Which versions of AnyDesk are affected by CVE-2024-52940?
AnyDesk versions up to and including 8.1.0 are affected by CVE-2024-52940.
5
Who is at risk from CVE-2024-52940?
Users who enable direct connections in AnyDesk are at risk from CVE-2024-52940.