CVE-2019-25261

anydesk: Unquoted Search Path or Element (CVE-2019-25261)

Description

AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially inject malicious executables. Attackers can exploit the unquoted binary path to place malicious files in service executable locations, potentially gaining elevated system privileges.

Source: NVD (NIST)

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

anydeskanydesk

Metrics

8.5
Source: cna-v4
8.0 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-02-03 15:16 UTC
CWE-428

Weakness classes (CWE)

  • CWE-428Base

    Unquoted Search Path or Element

    The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Translated2026-10-07 08:10 UTC· nvd@nist.gov
    • Translation: Title: AnyDesk de Anydesk, Description: AnyDesk 5.4.0 contiene una vulnerabilidad de ruta de servicio sin comillas en la configuración de su servicio de Windows que permite a atacantes locales inyectar potencialmente ejecutables maliciosos. Los atacantes pueden explotar la ruta binaria sin comillas para colocar archivos maliciosos en ubicaciones de ejecutables de servicio, obteniendo potencialmente privilegios de sistema elevados. → Title: AnyDesk, Description: AnyDesk 5.4.0 contiene una vulnerabilidad de ruta de servicio sin comillas en la configuración de su servicio de Windows que permite a atacantes locales inyectar potencialmente ejecutables maliciosos. Los atacantes pueden explotar la ruta binaria sin comillas para colocar archivos maliciosos en ubicaciones de ejecutables de servicio, obteniendo potencialmente privilegios de sistema elevados.