CVE-2021-44426
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is possible if the victim is using the AnyDesk Windows client to connect to a remote machine, if an attacker is also connected remotely with AnyDesk to the same remote machine. The upload is done without any approval or action taken by the victim.
Se ha detectado un problema en AnyDesk versiones anteriores a 6.2.6 y versiones 6.3.x anteriores a 6.3.5. Es posible subir un archivo arbitrario al directorio local ~/Downloads/ de la víctima si ésta usa el cliente Windows de AnyDesk para conectarse a una máquina remota, si un atacante también es conectado remotamente con AnyDesk a la misma máquina remota. La carga es realizada sin ninguna aprobación o acción por parte de la víctima
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-11-29 CVE Reserved
- 2022-09-12 CVE Published
- 2024-04-04 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://argus-sec.com/discovering-tunneling-service-security-flaws-in-anydesk-remote-application | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://anydesk.com/en/downloads/windows | 2022-09-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Anydesk Search vendor "Anydesk" | Anydesk Search vendor "Anydesk" for product "Anydesk" | < 6.2.6 Search vendor "Anydesk" for product "Anydesk" and version " < 6.2.6" | windows |
Affected
| ||||||
Anydesk Search vendor "Anydesk" | Anydesk Search vendor "Anydesk" for product "Anydesk" | >= 6.3.0 < 6.3.3 Search vendor "Anydesk" for product "Anydesk" and version " >= 6.3.0 < 6.3.3" | windows |
Affected
|