CVE-2019-25261
HIGH 7.8AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially inject malicious executables. Attackers can exploit the unquoted binary path to place malicious files in service executable locations, potentially gaining elevated system privileges.
Affected Applications in Environment
5
AnyDesk
vad 9.0.10
20 devices
AnyDesk
vad 9.6.12
1 device
AnyDesk
vad 9.6.11
1 device
AnyDesk
vad 7.0.15
1 device
AnyDesk
v8.1.4 (8.1.4.0)
1 device
Affected Devices
24
COX12
Windows
DESKTOP-7QO2ELA
Windows
DESKTOP-9UK6SOG
Windows
DESKTOP-BN4SD8A
Windows
DESKTOP-D9JRUTF
Windows
DESKTOP-FA7AMSL
Windows
DESKTOP-H4GPOR0
Windows
DESKTOP-OMEN
Windows
DESKTOP-QDORNBR
Windows
DPADVS-L1182PCN
Windows
DPCDIS-R90ZC0S3
Windows
DPEMAE-0243WQB
Windows
DPEMAE-640WDB4
Windows
DPEMAE-7242KJB
Windows
DPEMAE-8232PQN
Windows
DPEMAE-8232PS0
Windows
DPEMAE-8232PSR
Windows
DPEMAE-MJ0E03KT
Windows
DPENGR-305IT1
Windows
HDFS-16268K
Windows
MOHSEN-STRUC
Windows
SSWA-ATEM-D9010
Windows
USULOAN386
Windows
a02436282-HKW7GVPM04
Mac