CVE-2025-34499: AnyDesk 9.0.1 Unquoted Service Path Privilege Escalation Vulnerability
AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted service path configuration to inject malicious executables that will be run with high-level system permissions.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-34499?
CVE-2025-34499 is considered to have a high severity due to its potential for allowing local non-privileged users to execute code with elevated SYSTEM privileges.
How do I fix CVE-2025-34499?
To fix CVE-2025-34499, ensure that the service paths for AnyDesk are properly quoted to prevent exploitation.
What versions are affected by CVE-2025-34499?
CVE-2025-34499 affects AnyDesk versions 7.0.15 to 9.0.1.
Who can exploit CVE-2025-34499?
CVE-2025-34499 can be exploited by local non-privileged users on the system.
What type of vulnerability is CVE-2025-34499?
CVE-2025-34499 is an unquoted service path vulnerability.