HomeIntelligenceBrief
VULNERABILITY BRIEF🟡 Medium Vulnerability

AnyDesk Support Information Feature Vulnerability (CVE‑2025‑XXXX) Enables Local Denial‑of‑Service

A local privilege‑escalation flaw in AnyDesk's Support Information feature allows low‑privileged users to create arbitrary files and trigger a denial‑of‑service. The issue highlights the need for robust SOC 2 vulnerability‑management and control‑mapping practices.

LiveThreat™ Intelligence · 📅 July 09, 2026· 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
zerodayinitiative.com

AnyDesk “Send Support Information” Feature Allows Local DoS Attack

What Happened — A newly disclosed vulnerability (ZDI‑26‑401 / CVE‑2025‑XXXX) lets a low‑privileged attacker on a workstation create arbitrary files via the “Send Support Information” function in AnyDesk, ultimately causing a denial‑of‑service condition. The flaw requires local code execution; no remote exploit is known.

Why It Matters for Compliance & Audit Readiness

  • SOC 2 CC6.1 (System Operations) requires continuous monitoring for service‑disrupting conditions; a DoS vector like this must be tracked as a control failure.
  • Effective vulnerability‑management programs must map each finding to a specific control and retain evidence of remediation for auditability.
  • Demonstrating due‑diligence on third‑party remote‑support tools is a key component of the vendor‑risk portion of a SOC 2 audit.

Who Is Affected – Organizations that deploy AnyDesk for remote support across technology, professional services, and healthcare environments.

Recommended Actions

  • Add the AnyDesk “Send Support Information” component to your asset inventory and vulnerability‑scanning scope.
  • Map the finding to SOC 2 CC6.1 and CC7.2 (Change Management) and capture remediation tickets as audit evidence.
  • Restrict local execution of AnyDesk support features via endpoint hardening policies until a vendor patch is released.

Source: Zero Day Initiative advisory

Technical Notes – The issue is a local privilege‑escalation path that abuses a junction creation to write arbitrary files, leading to a denial‑of‑service. CVSS 4.7 (AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H). No remote exploit vector is known. Source: ZDI advisory

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-401/

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →