CVE-2019-25261

AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially inject malicious executables. Attackers can exploit the unquoted binary path to place malicious files in service executable locations, potentially gaining elevated system privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:anydesk:anydesk:5.4.0:*:*:*:*:windows:*:*

History

17 Jun 2026, 02:31

Type Values Removed Values Added
Summary
  • (es) AnyDesk 5.4.0 contiene una vulnerabilidad de ruta de servicio sin comillas en la configuración de su servicio de Windows que permite a atacantes locales inyectar potencialmente ejecutables maliciosos. Los atacantes pueden explotar la ruta binaria sin comillas para colocar archivos maliciosos en ubicaciones de ejecutables de servicio, obteniendo potencialmente privilegios de sistema elevados.

25 Feb 2026, 19:08

Type Values Removed Values Added
First Time Anydesk anydesk
Anydesk
CPE cpe:2.3:a:anydesk:anydesk:5.4.0:*:*:*:*:windows:*:*
References () http://anydesk.com - () http://anydesk.com - Product
References () https://www.exploit-db.com/exploits/47883 - () https://www.exploit-db.com/exploits/47883 - Exploit
References () https://www.vulncheck.com/advisories/anydesk-unquoted-service-path - () https://www.vulncheck.com/advisories/anydesk-unquoted-service-path - Third Party Advisory

03 Feb 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 15:16

Updated : 2026-06-17 02:31


NVD link : CVE-2019-25261

Mitre link : CVE-2019-25261

CVE.ORG link : CVE-2019-25261


JSON object : View

Products Affected

anydesk

  • anydesk
CWE
CWE-428

Unquoted Search Path or Element