---
cve: "CVE-2021-44426"
severity: "LOW"
cvss: 3.1
epss: "1%"
vendor: "n/a"
kev: false
exploited: false
published: "2022-09-12 21:15:09"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-17T07:47:54+02:00"
---

# CVE-2021-44426

> 3.1 LOW

## Beschreibung

An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is possible if the victim is using the AnyDesk Windows client to connect to a remote machine, if an attacker is also connected remotely with AnyDesk to the same remote machine. The upload is done without any approval or action taken by the victim.

## Referenzen

- <https://anydesk.com/en/downloads/windows>
- <https://argus-sec.com/discovering-tunneling-service-security-flaws-in-anydesk-remote-application/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2021-44426) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
