Impact
The flaw allows a local attacker who has obtained low‑privilege code execution to craft a junction that manipulates screen recording file handling, enabling the creation of arbitrary files. This leads to a denial‑of‑service condition on the affected AnyDesk installation. The weakness is a path manipulation issue (CWE‑59).
Affected Systems
AnyDesk – The AnyDesk 9.0.4 client is vulnerable to this flaw. This version is identified directly in the CNA CPE string. Users running AnyDesk 9.0.4 on any platform are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 5.5 indicates medium severity but the vulnerability requires low‑privilege code execution. EPSS is < 1% and the vulnerability is not listed in KEV, suggesting it is not a known, actively exploited flaw. The local exploit vector means that privileged users or malware that has achieved code execution on the host can trigger the denial‑of‑service behavior.
OpenCVE Enrichment