VYPR
High severity7.8NVD Advisory· Published Jun 19, 2026· Updated Jun 26, 2026

CVE-2016-20094

CVE-2016-20094

Description

AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers can insert malicious executables in the system root path that execute with elevated privileges during application startup or system reboot.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Anydesk/Anydesk2 versions
    cpe:2.3:a:anydesk:anydesk:2.5.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:anydesk:anydesk:2.5.0:*:*:*:*:*:*:*
    • (no CPE)range: =2.5.0

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.