5.5
CVSSv3

CVE-2024-12754

CVSSv4: NA | CVSSv3: 5.5 | CVSSv2: NA | VMScore: 650 | EPSS: 0.04044 | KEV: Not Included
Published: 30/12/2024 Updated: 30/12/2024

Vulnerability Summary

AnyDesk Link Following Vulnerability Permits Sensitive Information Disclosure

AnyDesk has a vulnerability that allows local attackers to get sensitive information. To exploit this, an attacker needs to run low-privileged code on the system. The issue is with how background images are handled. By making a junction, an attacker can read any files. This can help get stored credentials, causing more risks. This was known as ZDI-CAN-23940.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

anydesk anydesk