CVE-2016-20094

AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers can insert malicious executables in the system root path that execute with elevated privileges during application startup or system reboot.
Configurations

Configuration 1 (hide)

cpe:2.3:a:anydesk:anydesk:2.5.0:*:*:*:*:*:*:*

History

26 Jun 2026, 13:02

Type Values Removed Values Added
References () http://anydesk.com - () http://anydesk.com - Product
References () http://anydesk.com/download - () http://anydesk.com/download - Product
References () https://www.exploit-db.com/exploits/40410 - () https://www.exploit-db.com/exploits/40410 - Exploit, VDB Entry
References () https://www.vulncheck.com/advisories/anydesk-unquoted-service-path-elevation-of-privilege - () https://www.vulncheck.com/advisories/anydesk-unquoted-service-path-elevation-of-privilege - Third Party Advisory
CPE cpe:2.3:a:anydesk:anydesk:2.5.0:*:*:*:*:*:*:*
First Time Anydesk anydesk
Anydesk

19 Jun 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-19 15:16

Updated : 2026-06-26 13:02


NVD link : CVE-2016-20094

Mitre link : CVE-2016-20094

CVE.ORG link : CVE-2016-20094


JSON object : View

Products Affected

anydesk

  • anydesk
CWE
CWE-428

Unquoted Search Path or Element