CVE-2022-32450

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
18/07/2022
Last modified:
22/07/2022

Description

AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:anydesk:anydesk:7.0.9:*:*:*:*:*:*:*