CVE-2025-27919

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
06/11/2025
Last modified:
12/11/2025

Description

An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from the counterparty. Consequently, the attacker can later connect without this counterparty confirmation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:anydesk:anydesk:*:*:*:*:*:windows:*:* 9.0.4 (including)