Official Product Homepageproduct
http://anydesk.com/ CVE-2016-20094
HIGH
AnyDesk 2.5.0 Unquoted Service Path Elevation of Privilege
Record summary
CVE-2016-20094 has a selected CVSS score of 8.5 (high); EIP currently links 1 catalogued exploit.
Description
AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers can insert malicious executables in the system root path that execute with elevated privileges during application startup or system reboot.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 22, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
AnyDeskBrowse Anydesk / AnyDesk | CVE List | 2.5.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBAnyDesk 2.5.0 - Unquoted Service Path Privilege EscalationExploitDB exploitby TulpaNot analyzed1 file
References
5Product Referenceproduct
http://anydesk.com/download nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2016-20094 ExploitDB-40410exploit
https://www.exploit-db.com/exploits/40410 VulnCheck Advisory: AnyDesk 2.5.0 Unquoted Service Path Elevation of PrivilegeThird-party advisory
https://www.vulncheck.com/advisories/anydesk-unquoted-service-path-elevation-of-privilege