AnyDesk, another widely deployed remote-desktop tool, has had authentication-related and client vulnerabilities an attacker leverages against affected versions. The classes mirror the others: weaknesses in how the connection and unattended passwords are stored and protected (letting a local attacker recover them and then connect, durably via unattended access), and client-side flaws reachable through the application. AnyDesk also suffered a supply-chain security incident affecting its code-signing infrastructure, which raised the risk of trojanised or improperly-trusted clients. The practical attack is to fingerprint the version, match the advisory, and recover stored credentials where protection is weak.
# recover AnyDesk stored connection/unattended credentials on a host you can access
# configuration/app-data holds the settings and (version-dependent) recoverable secrets
dir "%APPDATA%\AnyDesk" "%ProgramData%\AnyDesk" 2>nul
type "%PROGRAMDATA%\AnyDesk\service.conf" 2>nul # example config location
# with the recovered unattended password + ID, connect from the attacker client
# match the AnyDesk version to the advisory for client/auth flaws
Exploitation notes#
- The stored-credential path is the reliable one: recover the unattended password from AnyDesk's configuration where its protection is weak, then connect at will, standing access via unattended access.
- Client-side and authentication flaws are version-specific; fingerprint the build (version detection) and match the advisory.
- The code-signing supply-chain incident is a trust consideration: clients from the affected period may not be trustworthy, and it underscores validating client integrity; it is context rather than a direct exploit step.
- Where no flaw applies, the configuration, exposure, and password attacks remain the route to AnyDesk access.