PT-2025-45346 · Anydesk · Anydesk

Published

2025-11-06

·

Updated

2025-12-08

·

CVE-2025-27918

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AnyDesk versions prior to 9.0.0
Description An issue exists where an integer overflow can lead to a heap-based buffer overflow. This occurs through the processing of a UDP packet, specifically during the handling of an Identity user image within the Discovery feature, or when a connection is established between AnyDesk clients.
Recommendations Update to AnyDesk version 9.0.0 or later.

Exploit

Fix

Integer Overflow

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-13991
CVE-2025-27918

Affected Products

Anydesk