Description
AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that can launch other applications.
Related CPE's
a
anydesk
anydesk
2
References
https://anydesk.com/cve/2021-40854/
Vendor Advisory
https://anydesk.com/cve/2021-40854/
Vendor Advisory
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8 · High
Information
Source identifier
Vulnerability status
Modified
Published
2021-10-14T03:15:07.643Z
4 years agoLast modified
2024-11-21T05:24:56.240Z
1 year ago