Логотип exploitDog
bind:CVE-2024-12754
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-12754

Количество 3

Количество 3

nvd логотип

CVE-2024-12754

около 1 года назад

AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of background images. By creating a junction, an attacker can abuse the service to read arbitrary files. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-23940.

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-rqf6-6p8f-f2pv

около 1 года назад

AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of background images. By creating a junction, an attacker can abuse the service to read arbitrary files. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-23940.

CVSS3: 5.5
EPSS: Низкий
fstec логотип

BDU:2025-02679

больше 1 года назад

Уязвимость программного обеспечения для удалённого доступа и управления AnyDesk, связанная с некорректным определением символических ссылок перед доступом к файлу, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-12754

AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of background images. By creating a junction, an attacker can abuse the service to read arbitrary files. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-23940.

CVSS3: 5.5
4%
Низкий
около 1 года назад
github логотип
GHSA-rqf6-6p8f-f2pv

AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of background images. By creating a junction, an attacker can abuse the service to read arbitrary files. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-23940.

CVSS3: 5.5
4%
Низкий
около 1 года назад
fstec логотип
BDU:2025-02679

Уязвимость программного обеспечения для удалённого доступа и управления AnyDesk, связанная с некорректным определением символических ссылок перед доступом к файлу, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 5.5
4%
Низкий
больше 1 года назад

Уязвимостей на страницу