Description
AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted service path configuration to inject malicious executables that will be run with high-level system permissions.
Problem types
CWE-428: Unquoted Search Path or Element
Product status
7.0.15
9.0.1
Credits
Parastou Razi
Milad Karimi (Ex3ptionaL)
References
www.exploit-db.com/exploits/52258 (ExploitDB-52258)
www.exploit-db.com/exploits/51968 (ExploitDB-51968)
anydesk.com (AnyDesk Homepage)
anydesk.com/download (AnyDesk Software Link)
www.vulncheck.com/...path-privilege-escalation-vulnerability (VulnCheck Advisory: AnyDesk 9.0.1 Unquoted Service Path Privilege Escalation Vulnerability)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.