Enterprise Risk Assessment: Security Risks of Deploying Claude Desktop and Cowork in Regulated Environments
Authors/Creators
Description
This paper presents a comprehensive security risk assessment for organizations considering deployment of Anthropic's Claude Desktop and Cowork in enterprise environments, particularly those handling personally identifiable information (PII), protected health information (PHI), financial data, or other regulated datasets. Drawing on publicly disclosed vulnerabilities by PromptArmor, LayerX, and Koi Research, as well as independent security research by the author, we identify systemic security deficiencies including silent file exfiltration via prompt injection, zero-click remote code execution through desktop extensions, command injection in official Anthropic extensions, world-writable SYSTEM service named pipe access controls, and VM boot media tampering enabling persistent backdoor implantation. We propose a defensive architecture of compensating controls for organizations that choose to deploy these tools despite the identified risks.
Files
Claude_Desktop_and_Cowork_Security_Vulnerabilities.pdf
Files
(114.4 kB)
| Name | Size | Download all |
|---|---|---|
|
md5:f0f8e7a910a2622425676f1b57c95f50
|
114.4 kB | Preview Download |
Additional details
Related works
- Is supplement to
- Publication: 10.5281/zenodo.19011781 (DOI)