Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g2cq-q859-8fm9

Опубликовано: 06 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.2

Описание

An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from the counterparty. Consequently, the attacker can later connect without this counterparty confirmation.

An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from the counterparty. Consequently, the attacker can later connect without this counterparty confirmation.

EPSS

Процентиль: 18%
0.00057
Низкий

8.2 High

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 8.2
nvd
3 месяца назад

An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from the counterparty. Consequently, the attacker can later connect without this counterparty confirmation.

CVSS3: 8.2
fstec
3 месяца назад

Уязвимость программного обеспечения для удалённого доступа и управления AnyDesk, связанная с ошибками обработки разрешений, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 18%
0.00057
Низкий

8.2 High

CVSS3

Дефекты

CWE-284