First published: Mon Nov 18 2024(Updated: )
AnyDesk through 8.1.0 on Windows, when Allow Direct Connections is enabled, inadvertently exposes a public IP address within network traffic. The attacker must know the victim's AnyDesk ID.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AnyDesk | <=8.1.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52940 is classified as a medium-severity vulnerability due to the potential exposure of a user's public IP address.
To mitigate CVE-2024-52940, users should disable the Allow Direct Connections feature in AnyDesk settings.
CVE-2024-52940 can lead to the unintentional exposure of a user's public IP address, increasing the risk of targeted attacks.
AnyDesk versions up to and including 8.1.0 are affected by CVE-2024-52940.
Users who enable direct connections in AnyDesk are at risk from CVE-2024-52940.