CVE-2026-15681
AnyDesk vulnerability analysis and mitigation

Overview

CVE-2026-15681 is a link-following denial-of-service vulnerability in AnyDesk that allows local attackers with low-privileged code execution to create a denial-of-service condition by abusing junction handling in screen recording file processing. The vulnerability was reported to AnyDesk on March 25, 2025, and publicly disclosed on July 13, 2026, after the vendor failed to provide a fix during a 16-month coordinated disclosure period, resulting in ZDI publishing it as a zero-day advisory. The affected version is AnyDesk 9.0.4. It carries a CVSS v3.0 base score of 4.7 (Medium) per ZDI, while NVD assigns a CVSS v3.1 score of 5.5 (Medium) (ZDI Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-59 (Improper Link Resolution Before File Access — 'Link Following'), specifically within AnyDesk's handling of screen recording files (GitHub Advisory). An attacker who has already obtained low-privileged local code execution can create a Windows junction (directory junction point) targeting a path that AnyDesk's service processes during screen recording operations; the service then follows the junction and creates arbitrary files at the attacker-controlled destination (ZDI Advisory). This attack requires no user interaction and has low attack complexity once local access is established, though it does require an initial foothold on the target system. The vulnerability was originally tracked as ZDI-CAN-26591 and was discovered by researcher Giuliano Sanfins from SiDi (ZDI Advisory).

Impact

Successful exploitation results in a denial-of-service condition on the affected system, with high availability impact and no confidentiality or integrity impact (ZDI Advisory, GitHub Advisory). By leveraging the junction abuse to create arbitrary files, an attacker can disrupt AnyDesk service operation or cause broader system instability, rendering the remote access functionality unavailable. The scope is limited to the local system and does not enable lateral movement or data exfiltration based on current analysis.

Exploitability

There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at the time of disclosure (ZDI Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and NVD's SSVC assessment confirms exploitation is currently "none" with the attack not being automatable. The EPSS score is approximately 0.10%, indicating a low near-term exploitation probability (GitHub Advisory). Notably, this was published as a zero-day advisory because AnyDesk's security team indicated the issue was "out of their scope" after 16 months of coordinated disclosure attempts (ZDI Advisory).

Exploitation steps

  1. Gain local access: Obtain low-privileged code execution on a system running AnyDesk 9.0.4, for example through a phishing attack, exploitation of another vulnerability, or use of existing credentials.
  2. Identify AnyDesk screen recording path: Locate the directory where AnyDesk writes screen recording files (typically within the AnyDesk application data directory or a user-writable path used by the AnyDesk service).
  3. Create a junction: Using a tool such as mklink /J (Windows built-in) or a custom script, create a directory junction at the expected screen recording file path that redirects to a sensitive or critical system directory (e.g., a system directory where arbitrary file creation would cause instability).
  4. Trigger screen recording: Initiate or wait for AnyDesk's service to process screen recording files, causing it to follow the junction and write arbitrary files to the attacker-specified destination.
  5. Achieve denial-of-service: The arbitrary file creation at the redirected path disrupts normal system or AnyDesk service operation, resulting in a denial-of-service condition (ZDI Advisory).

Indicators of compromise

  • File System: Unexpected directory junctions created in AnyDesk screen recording directories or application data paths; arbitrary files appearing in system directories not normally written to by AnyDesk.
  • Process: AnyDesk service process (anydesk.exe) writing files to unusual or unexpected filesystem locations outside its normal operational paths.
  • Logs: Windows Event Logs showing file creation events by the AnyDesk service in directories inconsistent with normal operation; errors or crashes in AnyDesk service logs coinciding with junction creation.
  • File System: Use of mklink or junction-creation utilities by low-privileged user accounts on systems running AnyDesk.

Mitigation and workarounds

ZDI notes that given the nature of the vulnerability, the primary mitigation is to restrict interaction with the AnyDesk product, as no vendor patch was available at the time of disclosure (ZDI Advisory). Organizations should restrict low-privileged code execution capabilities on systems running AnyDesk 9.0.4 to reduce the attack surface. Implementing file system monitoring to detect suspicious junction creation activities in AnyDesk-related directories is also recommended. Users should monitor for any updated AnyDesk releases that address this issue, as the vendor had not provided a fix after 16 months of coordinated disclosure.

Community reactions

The vulnerability attracted attention primarily due to AnyDesk's prolonged non-response during the 16-month coordinated disclosure period, with ZDI ultimately publishing it as a zero-day advisory after the vendor's support team stated the issue was "out of their scope" (ZDI Advisory). Security media outlet VPNcentral covered the disclosure alongside a related AnyDesk flaw, framing both as zero-day vulnerabilities enabling local denial-of-service attacks. A blog post on deafnews.it specifically highlighted the vendor's 16-month non-response as a notable failure in coordinated disclosure. Social media discussion on Mastodon referenced the vulnerability in the context of AnyDesk's disclosure handling.

Additional resources


SourceThis report was generated using AI

Related AnyDesk vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2016-20094HIGH8.5
  • AnyDesk logoAnyDesk
  • cpe:2.3:a:anydesk:anydesk
NoYesJun 19, 2026
CVE-2019-25261HIGH8.5
  • AnyDesk logoAnyDesk
  • cpe:2.3:a:anydesk:anydesk
NoYesFeb 03, 2026
CVE-2025-34499MEDIUM6.9
  • AnyDesk logoAnyDesk
  • cpe:2.3:a:anydesk:anydesk
NoYesDec 11, 2025
CVE-2026-15682MEDIUM5.5
  • AnyDesk logoAnyDesk
  • anydesk
NoYesJul 13, 2026
CVE-2026-15681MEDIUM5.5
  • AnyDesk logoAnyDesk
  • anydesk
NoYesJul 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management