Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-32r7-mgwg-67wq

Опубликовано: 19 июл. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.

AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.

EPSS

Процентиль: 31%
0.0012
Низкий

7.1 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.1
nvd
больше 3 лет назад

AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.

EPSS

Процентиль: 31%
0.0012
Низкий

7.1 High

CVSS3

Дефекты

CWE-59