CVE-2024-12754
CVSS 3.0 Score 5.5 of 10 (medium)
Details
Published Dec 30, 2024
CWE ID 59
Summary
CVE-2024-12754 is a vulnerability affecting AnyDesk that allows local attackers to disclose sensitive information. This issue arises from a flaw in the handling of background images, enabling an attacker to read arbitrary files by creating a junction. To exploit this vulnerability, an attacker must initially gain the ability to execute low-privileged code on the target system. Successful exploitation may result in the disclosure of stored credentials, potentially leading to further compromise. (ZDI-CAN-23940)
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- AnyDesk
Affected Vendors
- AnyDesk Software