Impact
This vulnerability involves the Send Support arbitrary files. By abusing this path‑resolution bug (CWE‑59), the attacker can cause the application or the underlying system to enter a denial‑of‑service state. The impact is a local denial of service; it does not provide elevated privileges or remote code execution.
Affected Systems
AnyDesk, version information not specified in the advisory. The flaw exists in AnyDesk installations that include the Send Support Information functionality. All users running AnyDesk should evaluate whether they have used that feature.
Risk and Exploitability
The CVSS score of 4.7 reflects a moderate impact, and the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. The vulnerability requires local access and low‑privileged execution, so the exploit requires the system with limited privileges. No exploits are reported in the wild, and there is no indication that the flaw is actively exploited. However, because the flaw can lead to a DoS condition, organizations should treat it as a moderate risk, especially in environments where AnyDesk features are used frequently.
OpenCVE Enrichment