ZDI-CAN-26591: ZDI-26-400: (0Day) AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of screen recording files. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-15681.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch ZDI-26-400
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26591?
The severity of ZDI-CAN-26591 is rated as medium with a score of 4.7.
How do I fix ZDI-CAN-26591?
To fix ZDI-CAN-26591, ensure that you update AnyDesk to the latest version that addresses this vulnerability.
What type of attack does ZDI-CAN-26591 facilitate?
ZDI-CAN-26591 facilitates a denial-of-service condition on affected installations of AnyDesk.
What is required for an attacker to exploit ZDI-CAN-26591?
An attacker must first obtain the ability to execute low-privileged code on the target system to exploit ZDI-CAN-26591.
What systems are affected by ZDI-CAN-26591?
ZDI-CAN-26591 affects installations of AnyDesk.