
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-27917 is a remote Denial of Service vulnerability in AnyDesk affecting multiple platforms. It stems from incorrect deserialization that causes failed memory allocation and a NULL pointer dereference, allowing unauthenticated remote attackers to crash the application. Affected versions include AnyDesk for Windows before 9.0.5, macOS before 9.0.1, Linux before 7.0.0, iOS before 7.1.2, and Android before 8.0.0. The vulnerability was published on November 6, 2025, and carries a CVSS v3.1 base score of 7.5 (High) (Red Hat CVE, ENISA EUVD).
The root cause is improper deserialization of network input (CWE-476: NULL Pointer Dereference), where maliciously crafted network requests trigger a failed memory allocation, ultimately causing a NULL pointer dereference within the AnyDesk application. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker who can reach the AnyDesk service. A proof-of-concept and technical analysis are documented in a Czech Technical University thesis (CTU Thesis).
Successful exploitation causes the AnyDesk application to crash, resulting in a complete loss of availability for the remote desktop service on the affected endpoint. Since AnyDesk is widely used for remote administration and support, exploitation could disrupt business operations, interrupt active remote sessions, and deny legitimate users access to managed systems. There is no confidentiality or integrity impact associated with this vulnerability — the sole consequence is application unavailability (Red Hat CVE, ENISA EUVD).
A proof-of-concept exploit is publicly available in a Czech Technical University thesis published in November 2025, but there is no evidence of active in-the-wild exploitation at this time (CTU Thesis). The EPSS score is approximately 0.183%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage exists via Nessus (plugin 298245) and Qualys (plugin 386508) (Tenable).
AnyDesk.exe (Windows) or equivalent AnyDesk process without user-initiated action; repeated process restarts if configured for auto-recovery.Users should immediately update AnyDesk to the fixed versions: Windows 9.0.5 or later, macOS 9.0.1 or later, Linux 7.0.0 or later, iOS 7.1.2 or later, and Android 8.0.0 or later (AnyDesk Changelog). As a temporary workaround, restrict network access to the AnyDesk application using firewall rules or network segmentation to limit exposure to trusted IP ranges only. If AnyDesk is not actively needed, consider disabling the service until patching is complete.
Red Hat has tracked and published an advisory for this CVE, and ENISA has catalogued it under EUVD-2025-38151 (Red Hat CVE, ENISA EUVD). Spain's INCIBE-CERT also issued an early warning advisory (INCIBE). No significant social media discussion or notable researcher commentary beyond the academic PoC has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."