vendor:
AnyDesk
by:
scryh
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: AnyDesk
Affected Version From: 5.5.2
Affected Version To: 5.5.2
Patch Exists: YES
Related CWE: N/A
CPE: //a:anydesk:anydesk:5.5.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2020
AnyDesk 5.5.2 – Remote Code Execution
AnyDesk 5.5.2 is vulnerable to Remote Code Execution. An attacker can send a specially crafted packet to the AnyDesk service on port 50001 to execute arbitrary code. The packet contains a malicious payload which is then executed on the target system.
Mitigation:
Update to the latest version of AnyDesk.