Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-32450

Опубликовано: 18 июл. 2022
Источник: nvd
CVSS3: 7.1
EPSS Низкий

Описание

AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:anydesk:anydesk:7.0.9:*:*:*:*:*:*:*

EPSS

Процентиль: 31%
0.0012
Низкий

7.1 High

CVSS3

Дефекты

CWE-59

Связанные уязвимости

CVSS3: 7.1
github
больше 3 лет назад

AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.

EPSS

Процентиль: 31%
0.0012
Низкий

7.1 High

CVSS3

Дефекты

CWE-59