PT-2024-8638 · Anydesk · Anydesk

Ebrahim Shafiei

+1

·

Published

2024-11-17

·

Updated

2025-03-11

·

CVE-2024-52940

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions AnyDesk versions 8.1.0 and lower
Description The issue is related to the "Allow Direct Connections" feature of the AnyDesk remote desktop software, which inadvertently exposes a public IP address within network traffic when enabled. An attacker must know the victim's AnyDesk ID to exploit this issue. This may allow a remote attacker to disclose protected information about the IP address of the target system.
Recommendations For AnyDesk versions 8.1.0 and lower, consider disabling the "Allow Direct Connections" feature until a patch is available. Restrict access to the affected feature to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10229
CVE-2024-52940

Affected Products

Anydesk