CVE-2026-15682 is a denial-of-service vulnerability in AnyDesk's support information feature. Local attackers with low-privileged code execution can exploit it by creating a junction to create arbitrary files, leading to a denial-of-service condition. This vulnerability requires an attacker to first obtain the ability to execute low-privileged code on the target system. Users should be aware of the potent [truncated]
CVE-2026-15681 is a medium-severity vulnerability in AnyDesk that allows local attackers to create a denial-of-service condition. To exploit this vulnerability, an attacker must first obtain the ability to execute low-privileged code on the target system. The flaw exists within the handling of screen recording files, where an attacker can create a junction to abuse the service and create arbitrary files, [truncated]
CVE-2016-20094 is a HIGH-severity vulnerability (CVSS Score: 8.5) affecting AnyDesk 2.5.0. The issue is an unquoted service path vulnerability, which allows local users to execute arbitrary code with SYSTEM privileges by inserting malicious executables in the system root path. This can occur during application startup or system reboot. Defenders should prioritize patching or mitigating this vulnerability [truncated]