ZDI-26-401: (0Day) AnyDesk Support Information Link Following Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Send Support Information feature. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-15682.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AnyDeskto a version that resolves this vulnerability.Patch ZDI-26-401 - Compensating control
Mitigate the local denial-of-service by restricting or disabling AnyDesk's 'Send Support Information' feature until the ZDI-26-401 fix is applied.
Event History
Frequently Asked Questions
What is the severity of ZDI-26-401?
The severity of ZDI-26-401 is medium, with a score of 4.7.
How do I fix ZDI-26-401?
To fix ZDI-26-401, ensure you update AnyDesk to the latest version that addresses this denial-of-service vulnerability.
What type of attack does ZDI-26-401 facilitate?
ZDI-26-401 allows local attackers to create a denial-of-service condition on affected installations of AnyDesk.
What privileges are required to exploit ZDI-26-401?
An attacker must have the ability to execute low-privileged code on the target system to exploit ZDI-26-401.
What impact does ZDI-26-401 have on AnyDesk?
The impact of ZDI-26-401 on AnyDesk is a potential denial-of-service condition that affects the application’s availability.