ZDI-26-400: (0Day) AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of screen recording files. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-15681.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-26-400
Event History
Frequently Asked Questions
What is the severity of ZDI-26-400?
The severity of ZDI-26-400 is classified as medium with a score of 4.7.
How do I fix ZDI-26-400?
To fix ZDI-26-400, ensure that you apply the latest security updates provided by AnyDesk.
What types of systems are affected by ZDI-26-400?
ZDI-26-400 affects installations of AnyDesk where local attackers can execute low-privileged code.
What impact does ZDI-26-400 have on system functionality?
ZDI-26-400 allows attackers to create a denial-of-service condition on affected AnyDesk installations.
Can external attackers exploit ZDI-26-400?
No, ZDI-26-400 requires an attacker to have local access to the system in order to exploit the vulnerability.