An issue was discovered in AnyDesk before 6.2.6 and 6.3.x...
High severity
Unreviewed
Published
Sep 13, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Sep 12, 2022
Published to the GitHub Advisory Database
Sep 13, 2022
Last updated
Jan 27, 2023
An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is possible if the victim is using the AnyDesk Windows client to connect to a remote machine, if an attacker is also connected remotely with AnyDesk to the same remote machine. The upload is done without any approval or action taken by the victim.
References