Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
AnyDesk Support Information Link Following Denial-of-Service Vulnerability
Vulnerability Description
AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the Send Support Information feature. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26645.
CVSS Information
N/A
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Vulnerability Title
AnyDesk 后置链接漏洞
Vulnerability Description
AnyDesk是德国AnyDesk公司的一款远程桌面连接软件。 AnyDesk 9.0.4版本存在后置链接漏洞,该漏洞源于Send Support Information功能中的后置链接问题,可能允许本地攻击者在获取低权限代码执行能力后,通过创建连接点滥用服务创建任意文件,进而导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A