Arbitrary File Write Vulnerability in AnyDesk by AnyDesk GmbH
CVE-2022-32450
7.1HIGH
What is CVE-2022-32450?
A local privilege escalation vulnerability exists in AnyDesk 7.0.9 due to improper handling of symbolic links. This flaw permits a local user to gain SYSTEM privileges by exploiting the ability to write to their own %APPDATA% directory. When chat-room data is written to this location, it operates with elevated privileges, potentially allowing an attacker to perform unauthorized actions on the system.