AnyDesk “Send Support Information” Feature Allows Local DoS Attack
What Happened — A newly disclosed vulnerability (ZDI‑26‑401 / CVE‑2025‑XXXX) lets a low‑privileged attacker on a workstation create arbitrary files via the “Send Support Information” function in AnyDesk, ultimately causing a denial‑of‑service condition. The flaw requires local code execution; no remote exploit is known.
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 (System Operations) requires continuous monitoring for service‑disrupting conditions; a DoS vector like this must be tracked as a control failure.
- Effective vulnerability‑management programs must map each finding to a specific control and retain evidence of remediation for auditability.
- Demonstrating due‑diligence on third‑party remote‑support tools is a key component of the vendor‑risk portion of a SOC 2 audit.
Who Is Affected – Organizations that deploy AnyDesk for remote support across technology, professional services, and healthcare environments.
Recommended Actions –
- Add the AnyDesk “Send Support Information” component to your asset inventory and vulnerability‑scanning scope.
- Map the finding to SOC 2 CC6.1 and CC7.2 (Change Management) and capture remediation tickets as audit evidence.
- Restrict local execution of AnyDesk support features via endpoint hardening policies until a vendor patch is released.
Source: Zero Day Initiative advisory
Technical Notes – The issue is a local privilege‑escalation path that abuses a junction creation to write arbitrary files, leading to a denial‑of‑service. CVSS 4.7 (AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H). No remote exploit vector is known. Source: ZDI advisory