The specific flaw exists within the handling of background images. By creating a junction, an attacker can abuse the service to read arbitrary files. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-23940.
Metrics
Affected Vendors & Products
| Source | ID | Title | 
|---|---|---|
  EUVD | 
                EUVD-2024-51089 | AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of background images. By creating a junction, an attacker can abuse the service to read arbitrary files. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-23940. | 
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers | 
|---|---|
| https://www.zerodayinitiative.com/advisories/ZDI-24-1711/ | 
                     | 
            
Thu, 14 Aug 2025 19:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| CPEs | cpe:2.3:a:anydesk:anydesk:8.0.9:*:*:*:*:windows:*:* | 
Tue, 31 Dec 2024 19:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Mon, 30 Dec 2024 17:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of background images. By creating a junction, an attacker can abuse the service to read arbitrary files. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-23940. | |
| Title | AnyDesk Link Following Information Disclosure Vulnerability | |
| Weaknesses | CWE-59 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_0
         
  | 
Status: PUBLISHED
Assigner: zdi
Published:
Updated: 2024-12-31T19:09:11.684Z
Reserved: 2024-12-18T16:30:30.396Z
Link: CVE-2024-12754
Updated: 2024-12-31T19:09:03.179Z
Status : Analyzed
Published: 2024-12-30T17:15:07.127
Modified: 2025-08-14T18:46:10.360
Link: CVE-2024-12754
No data.
                        OpenCVE Enrichment
                    Updated: 2025-07-12T22:09:37Z
 EUVD