AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers can insert malicious executables in the system root path that execute with elevated privileges during application startup or system reboot.
Metrics
Affected Vendors & Products
References
History
Fri, 19 Jun 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Anydesk
Anydesk anydesk |
|
| Vendors & Products |
Anydesk
Anydesk anydesk |
Fri, 19 Jun 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers can insert malicious executables in the system root path that execute with elevated privileges during application startup or system reboot. | |
| Title | AnyDesk 2.5.0 Unquoted Service Path Elevation of Privilege | |
| Weaknesses | CWE-428 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-19T14:16:47.250Z
Reserved: 2026-06-19T13:25:53.817Z
Link: CVE-2016-20094
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-19T20:45:03Z