vendor:
AnyDesk
by:
Tulpa
7.5
CVSS
HIGH
Unquoted Service Path Elevation of Privilege
428
CWE
Product Name: AnyDesk
Affected Version From: 2.5.2000
Affected Version To: 2.5.2000
Patch Exists: NO
Related CWE:
CPE: a:anydesk:anydesk:2.5.0
Platforms Tested: Windows 10 Professional x64, Windows XP SP3 x86, Windows Server 2008 R2 x64
2016
AnyDesk 2.5.0 Unquoted Service Path Elevation of Privilege
The Anydesk installs as a service with an unquoted service path running with SYSTEM privileges. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system.
Mitigation:
The vendor should fix the unquoted service path by enclosing the path in double quotes.