AnyDesk Zero-Day Flaw Allows Local Attackers to Trigger System-Wide Denial-of-Service
ID: 9f93362f-cd39-56b6-8119-a0caa240b217
STIX ID: report--9f93362f-cd39-56b6-8119-a0caa240b217
Feed Name: GBHackers
A newly disclosed AnyDesk zero-day (CVE-2026-15682) allows a low-privileged local attacker to abuse the "Send Support Information" feature by creating filesystem junctions that redirect where the service writes files, enabling arbitrary file creation and potentially causing a denial-of-service; ZDI published the advisory with a CVSS v3 score of 4.7, no vendor patch was available at disclosure, and mitigations include restricting local access, enforcing least-privilege, and monitoring reparse-point/junction creation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
