CVE-2025-27917
AnyDesk vulnerability analysis and mitigation

Overview

CVE-2025-27917 is a remote Denial of Service vulnerability in AnyDesk affecting multiple platforms. It stems from incorrect deserialization that causes failed memory allocation and a NULL pointer dereference, allowing unauthenticated remote attackers to crash the application. Affected versions include AnyDesk for Windows before 9.0.5, macOS before 9.0.1, Linux before 7.0.0, iOS before 7.1.2, and Android before 8.0.0. The vulnerability was published on November 6, 2025, and carries a CVSS v3.1 base score of 7.5 (High) (Red Hat CVE, ENISA EUVD).

Technical details

The root cause is improper deserialization of network input (CWE-476: NULL Pointer Dereference), where maliciously crafted network requests trigger a failed memory allocation, ultimately causing a NULL pointer dereference within the AnyDesk application. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker who can reach the AnyDesk service. A proof-of-concept and technical analysis are documented in a Czech Technical University thesis (CTU Thesis).

Impact

Successful exploitation causes the AnyDesk application to crash, resulting in a complete loss of availability for the remote desktop service on the affected endpoint. Since AnyDesk is widely used for remote administration and support, exploitation could disrupt business operations, interrupt active remote sessions, and deny legitimate users access to managed systems. There is no confidentiality or integrity impact associated with this vulnerability — the sole consequence is application unavailability (Red Hat CVE, ENISA EUVD).

Exploitability

A proof-of-concept exploit is publicly available in a Czech Technical University thesis published in November 2025, but there is no evidence of active in-the-wild exploitation at this time (CTU Thesis). The EPSS score is approximately 0.183%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage exists via Nessus (plugin 298245) and Qualys (plugin 386508) (Tenable).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or network-accessible hosts running AnyDesk versions up to 9.0.4 (Windows), using tools like Shodan, Censys, or network scanners targeting AnyDesk's default listening port (7070/TCP).
  2. Craft malicious payload: Construct a specially crafted network packet or deserialization payload designed to trigger incorrect deserialization within the AnyDesk protocol handler, as detailed in the public PoC research (CTU Thesis).
  3. Send payload: Transmit the malformed request to the target AnyDesk instance over the network without requiring any credentials or user interaction.
  4. Trigger crash: The malformed deserialization input causes a failed memory allocation, leading to a NULL pointer dereference and application crash, rendering the AnyDesk service unavailable on the target system.

Indicators of compromise

  • Network: Unexpected or malformed connection attempts to AnyDesk's listening port (default 7070/TCP) from unknown or external IP addresses; unusual spikes in connection attempts to AnyDesk endpoints.
  • Logs: AnyDesk application crash logs or Windows Event Log entries (Event ID 1000/1001) indicating application faults in the AnyDesk process; crash dump files generated in the AnyDesk installation or temp directory.
  • Process: Sudden termination of the AnyDesk.exe (Windows) or equivalent AnyDesk process without user-initiated action; repeated process restarts if configured for auto-recovery.

Mitigation and workarounds

Users should immediately update AnyDesk to the fixed versions: Windows 9.0.5 or later, macOS 9.0.1 or later, Linux 7.0.0 or later, iOS 7.1.2 or later, and Android 8.0.0 or later (AnyDesk Changelog). As a temporary workaround, restrict network access to the AnyDesk application using firewall rules or network segmentation to limit exposure to trusted IP ranges only. If AnyDesk is not actively needed, consider disabling the service until patching is complete.

Community reactions

Red Hat has tracked and published an advisory for this CVE, and ENISA has catalogued it under EUVD-2025-38151 (Red Hat CVE, ENISA EUVD). Spain's INCIBE-CERT also issued an early warning advisory (INCIBE). No significant social media discussion or notable researcher commentary beyond the academic PoC has been observed.

Additional resources


SourceThis report was generated using AI

Related AnyDesk vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2016-20094HIGH8.5
  • AnyDesk logoAnyDesk
  • cpe:2.3:a:anydesk:anydesk
NoYesJun 19, 2026
CVE-2019-25261HIGH8.5
  • AnyDesk logoAnyDesk
  • cpe:2.3:a:anydesk:anydesk
NoYesFeb 03, 2026
CVE-2025-34499MEDIUM6.9
  • AnyDesk logoAnyDesk
  • cpe:2.3:a:anydesk:anydesk
NoYesDec 11, 2025
CVE-2026-15682MEDIUM5.5
  • AnyDesk logoAnyDesk
  • anydesk
NoYesJul 13, 2026
CVE-2026-15681MEDIUM5.5
  • AnyDesk logoAnyDesk
  • cpe:2.3:a:anydesk:anydesk
NoYesJul 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management