Arbitrary File Upload Vulnerability in AnyDesk Remote Desktop Software
CVE-2021-44426
8.8HIGH
What is CVE-2021-44426?
An arbitrary file upload vulnerability exists in AnyDesk versions prior to 6.2.6 and 6.3.x before 6.3.5. This issue allows an attacker, connected to the same remote machine, to upload files to the victim’s local ~/Downloads/ directory without the victim's consent or action. The risk associated with this vulnerability emphasizes the importance of secure remote desktop implementations.