ZDI-24-1711: AnyDesk Link Following Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of background images. By creating a junction, an attacker can abuse the service to read arbitrary files. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise.
Other sources
This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2024-12754.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1711?
The severity of ZDI-24-1711 is considered critical due to the potential for sensitive information disclosure.
How do I fix ZDI-24-1711?
To fix ZDI-24-1711, ensure you update to the latest version of AnyDesk that addresses this vulnerability.
Who is affected by ZDI-24-1711?
AnyDesk users who have not applied security updates are affected by ZDI-24-1711.
What type of attack does ZDI-24-1711 involve?
ZDI-24-1711 involves local attacks that require low-privileged code execution to exploit the vulnerability.
What is the impact of ZDI-24-1711?
The impact of ZDI-24-1711 includes potentially allowing local attackers to disclose sensitive information on the affected system.