vendor:
AnyDesk
by:
SajjadBnd
7.8
CVSS
HIGH
Unquoted Service Path
428
CWE
Product Name: AnyDesk
Affected Version From: AnyDesk 5.4.0
Affected Version To: AnyDesk 5.4.0
Patch Exists: NO
Related CWE:
CPE: a:anydesk:anydesk:5.4.0
Platforms Tested: Windows 10 x64
2019
AnyDesk 5.4.0 – Unquoted Service Path
The AnyDesk service in version 5.4.0 has an unquoted service path vulnerability, which allows an attacker to escalate privileges by placing a malicious executable in a directory higher in the system's path than the legitimate AnyDesk executable.
Mitigation:
To mitigate this vulnerability, the vendor should update the service configuration to include quotes around the path to the AnyDesk executable. Users can also mitigate this vulnerability by manually updating the service configuration to include quotes around the path.