Impact
The flaw allows a local attacker who has obtained low‑privilege code execution to craft a junction that manipulates screen recording file handling, enabling the creation of arbitrary files. This leads to a denial‑of-service condition on the affected AnyDesk installation. The weakness is a path manipulation issue (CWE‑59).
Affected Systems
AnyDesk – All installations of the AnyDesk client are vulnerable. No specific version information is disclosed, so any installed copy may be affected.
Risk and Exploitability
The CVSS score of 4.7 indicates medium severity but the vulnerability requires low‑privilege code execution. EPSS is < 1% and the vulnerability is not listed in KEV, suggesting it is not a known, actively exploited flaw. The local exploit vector means that privileged users or malware that has achieved code execution on the host can trigger the denial‑of‑service behavior.
OpenCVE Enrichment