ZDI-CAN-26645: ZDI-26-401: (0Day) AnyDesk Support Information Link Following Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Send Support Information feature. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-15682.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26645?
The severity of ZDI-CAN-26645 is rated at 4.7 on the CVSS scale.
How do I fix ZDI-CAN-26645?
To fix ZDI-CAN-26645, update AnyDesk to the latest version provided by the vendor.
What type of vulnerability is ZDI-CAN-26645?
ZDI-CAN-26645 is a denial-of-service vulnerability affecting AnyDesk installations.
Who can exploit ZDI-CAN-26645?
Local attackers with the ability to execute low-privileged code can exploit ZDI-CAN-26645.
What is the potential impact of ZDI-CAN-26645?
The potential impact of ZDI-CAN-26645 is to create a denial-of-service condition on affected AnyDesk installations.