AnyDesk
cpe:2.3:a:anydesk:anydesk:*:*:*:*:*:*:*, +3 more
- <= 9.0.4
A vulnerability exists in AnyDesk versions through 9.0.4, allowing a remotely connected user with 'Control my device' permission to alter remote AnyDesk settings. The user can create a password for the Full Access profile without requiring confirmation from the other party. This enables the user to connect later without needing counterparty approval.
Exploitation of this vulnerability allows for unauthorized access to a user's device via the Full Access profile, bypassing the usual confirmation process.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.