Description
AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The specific flaw exists within the handling of screen recording files. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26591.
Published: 2026-07-13
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw allows a local attacker who has obtained low‑privilege code execution to craft a junction that manipulates screen recording file handling, enabling the creation of arbitrary files. This leads to a denial‑of-service condition on the affected AnyDesk installation. The weakness is a path manipulation issue (CWE‑59).

Affected Systems

AnyDesk – All installations of the AnyDesk client are vulnerable. No specific version information is disclosed, so any installed copy may be affected.

Risk and Exploitability

The CVSS score of 4.7 indicates medium severity but the vulnerability requires low‑privilege code execution. EPSS is < 1% and the vulnerability is not listed in KEV, suggesting it is not a known, actively exploited flaw. The local exploit vector means that privileged users or malware that has achieved code execution on the host can trigger the denial‑of‑service behavior.

Generated by OpenCVE AI on July 31, 2026 at 11:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest AnyDesk security update to eliminate the screen recording handling flaw.
  • Restrict local user privileges to prevent arbitrary code execution that could create malicious junctions.
  • Disable or revoke permissions for the AnyDesk screen recording feature if it is not required.
  • Monitor the system for unexpected file creation in the AnyDesk directory and review junction usage logs.

Generated by OpenCVE AI on July 31, 2026 at 11:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Anydesk
Anydesk anydesk
Vendors & Products Anydesk
Anydesk anydesk

Mon, 13 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of screen recording files. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26591.
Title AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability
Weaknesses CWE-59
References
Metrics cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: zdi

Published:

Updated: 2026-07-14T12:48:29.853Z

Reserved: 2026-07-13T21:29:16.312Z

Link: CVE-2026-15681

cve-icon Vulnrichment

Updated: 2026-07-14T12:48:25.823Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T11:15:05Z

Weaknesses
  • CWE-59

    Improper Link Resolution Before File Access ('Link Following')