Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4wh5-g47w-7vfc

Опубликовано: 12 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 6.9

Описание

AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted service path configuration to inject malicious executables that will be run with high-level system permissions.

AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted service path configuration to inject malicious executables that will be run with high-level system permissions.

EPSS

Процентиль: 24%
0.0008
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-428

Связанные уязвимости

nvd
около 2 месяцев назад

AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted service path configuration to inject malicious executables that will be run with high-level system permissions.

EPSS

Процентиль: 24%
0.0008
Низкий

6.9 Medium

CVSS4

Дефекты

CWE-428