---
id: CVE-2016-20094
title: >-
  AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows
  local users to execute arbitrary code with SYSTEM privileges by exploiting the
  service installation
summary: >-
  AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows
  local users to execute arbitrary code with SYSTEM privileges by exploiting the
  service installation. Attackers can insert malicious executables in the system
  root …
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-428
vendor: anydesk
product: anydesk
affected:
  - anydesk = 2.5.0
published: '2026-06-19'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T09:10:00.157'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2016-20094'
references:
  - url: 'http://anydesk.com'
    label: disclosure@vulncheck.com
  - url: 'http://anydesk.com/download'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/40410'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/anydesk-unquoted-service-path-elevation-of-privilege
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00197
epssPercentile: 0.08416
ingestedAt: '2026-09-29T09:30:49.074Z'
---

## Overview

AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers can insert malicious executables in the system root path that execute with elevated privileges during application startup or system reboot.

## Affected

- `anydesk = 2.5.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
