CVE-2025-34499: Anydesk

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

AnyDesk 7.0.15 and 9.0.1 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated SYSTEM privileges. Attackers can exploit the unquoted service path configuration to inject malicious executables that will be run with high-level system permissions.

Affected products

  • Anydesk Anydesk: version 7.0.15 only; version 9.0.1 only

Published 2025-12-11. Last modified 2026-06-17.