CVE-2020-13160 DetailCurrent DescriptionAnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution. Analysis DescriptionAnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution. SeverityCVSS 3.x Severity and Metrics: NIST:NVD Vector:NVD Vector: | |
Hyperlink | Resource |
---|---|
http://packetstormsecurity.com/files/158291/AnyDesk-GUI-Format-String-Write.html | ExploitThird Party AdvisoryVDB Entry |
http://packetstormsecurity.com/files/161628/AnyDesk-5.5.2-Remote-Code-Execution.html | ExploitThird Party AdvisoryVDB Entry |
https://devel0pment.de/?p=1881 | ExploitThird Party Advisory |
https://download.anydesk.com/changelog.txt | Release NotesVendor Advisory |

Anydesk Download For Windows 10
Weakness Enumeration
CWE-ID | CWE Name | Source |
---|---|---|
CWE-134 | Use of Externally-Controlled Format String | NIST |
Anydesk Promo Code
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution. View Analysis Description Analysis Description. When you first install the AnyDesk software on your computer, you get a numerical ID code that is used for identifying your device. You pair and connect your two devices using that AnyDesk ID code which is visible to you whenever you open the ANyDesk app. Basically, that ID represents your device’s address.
Known Affected Software Configurations Switch to CPE 2.2
Denotes Vulnerable Software
Are we missing a CPE here? Please let us know.
Change History
4 change records found show changes
Anydesk Access Code
Quick Info
CVE Dictionary Entry:CVE-2020-13160
NVD Published Date:
06/09/2020
NVD Last Modified:
03/15/2021
Source:
MITRE
