Cyber Security News

Critical AnyDesk Vulnerability Let Attackers Uncover User IP Address

A critical vulnerability in AnyDesk, a popular remote desktop application, has been discovered that could allow attackers to expose users’ IP addresses.

The flaw, identified as CVE-2024-52940, affects AnyDesk versions 8.1.0 and earlier on Windows systems.

Security researcher Ebrahim Shafiei (EbraSha) discovered this vulnerability on October 27, 2024. It exploits AnyDesk’s “Allow Direct Connections” feature.

When this option is enabled and the connection port is set to 7070 on the attacker’s system, it becomes possible to retrieve the public IP address of a target using only their AnyDesk ID, without any configuration changes on the target system.

This zero-day vulnerability poses significant privacy risks, inadvertently exposing sensitive IP information within network traffic.

Besides this, security analysts identified that the attackers can easily identify this information through network sniffing on their own systems. Moreover, if both the attacker and the target are on the same local network, the target’s private IP address may also be accessible.

Maximizing Cybersecurity ROI: Expert Tips for SME & MSP Leaders – Attend Free Webinar

AnyDesk Vulnerability Details

The flaw has been officially registered as CVE-2024-52940 by the National Institute of Standards and Technology (NIST), Tenable, and MITRE. It has been assigned a CVSS base score of 7.5, indicating a high severity level.

Key aspects of the vulnerability include:-

  • Ability to retrieve the public IP address of a remote system using only the AnyDesk ID
  • Potential for private IP detection within local network connections
  • No complex dependencies or specific prerequisites required to exploit the vulnerability
Network traffic capture using the Abdal Sniffer tool (Source – GitHub)

This vulnerability raises serious concerns about user privacy and security. Malicious actors could potentially use this flaw to:-

  1. Track user locations
  2. Launch targeted attacks
  3. Bypass certain security measures that rely on IP-based authentication

As of now, no official patch or fixed version from AnyDesk is available to address this vulnerability. Users are advised to take the following precautions:

  1. Disable the “Allow Direct Connections” feature in AnyDesk settings if not strictly necessary
  2. Monitor for any suspicious connection attempts
  3. Use a VPN service to mask your real IP address when using AnyDesk
  4. Keep AnyDesk updated and watch for any security announcements from the company

AnyDesk users should remain vigilant and consider alternative remote desktop solutions until a fix is released. The cybersecurity community eagerly awaits an official response and patch from AnyDesk to address this critical vulnerability.

As remote work continues to be prevalent, both users and software developers must prioritize security in remote access tools.

Are you from SOC/DFIR Teams? – Analyse Malware Files & Links with ANY.RUN -> Try for Free

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

3 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

13 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

14 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

14 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

14 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

15 hours ago