AnyDesk Zero-Day Flaw Lets Low-Privileged Attackers Trigger Denial-of-Service

A newly disclosed zero-day vulnerability in the popular remote access software AnyDesk, tracked as CVE-2026-15682, allows local attackers with low privileges to trigger a denial-of-service (DoS) condition on affected systems.

The issue stems from improper handling of file operations within the application’s “Send Support Information” feature, exposing systems to disruption through abuse of filesystem junctions.

The vulnerability stems from insufficient validation of file paths during support data collection. By crafting a malicious junction (a type of filesystem redirection mechanism in Windows environments), an attacker can manipulate the application into creating arbitrary files in unintended locations.

AnyDesk Zero-Day Vulnerability

While the flaw does not directly enable privilege escalation or remote code execution, it provides a reliable mechanism to destabilize the system, potentially causing service crashes or resource exhaustion.

To exploit CVE-2026-15682, an attacker must first gain the ability to execute code on the target machine with low-level privileges.

This requirement limits remote exploitation scenarios but makes the vulnerability particularly relevant in post-compromise situations, where attackers often seek to disrupt operations, evade detection, or interfere with incident response workflows.

Giuliano Sanfins note that the abuse of junctions in Windows environments has long been a common technique for exploiting improper file handling logic.

In this case, the Send Support Information feature becomes an unintended vector for file system manipulation, allowing attackers to redirect file creation operations to sensitive or critical paths. This can lead to application instability or broader system-level denial-of-service conditions.

The vulnerability was discovered and reported by Giuliano Sanfins from SiDi (0x_alibabas) through Trend Micro’s Zero Day Initiative (ZDI). ZDI initially submitted the report to the vendor on March 31, 2025, and subsequently made multiple attempts to confirm receipt and obtain status updates.

Despite repeated follow-ups, the issue remained unresolved, eventually leading ZDI to announce its intention to publish the vulnerability as a zero-day advisory on June 26, 2026.

The lack of timely remediation or clear communication from the vendor raises concerns about patch management and coordinated disclosure practices, especially for widely deployed remote access tools like AnyDesk.

At the time of disclosure, no official patch or fix has been released. As a result, mitigation options are limited. Security experts recommend restricting interaction with the AnyDesk application, particularly the affected support feature, and minimizing exposure by enforcing strict access controls.

Monitoring for unusual file system activity and limiting local execution capabilities can also help reduce the risk of exploitation.

Given the widespread use of AnyDesk in both enterprise and remote work environments, organizations are urged to assess their exposure and implement compensating controls until a vendor patch becomes available.

Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *