CVE Vulnerabilities

CVE-2025-27919

Published: Nov 06, 2025 | Modified: Nov 07, 2025
CVSS 3.x
8.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the Control my device permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from the counterparty. Consequently, the attacker can later connect without this counterparty confirmation.

Affected Software

Name Vendor Start Version End Version
Anydesk Anydesk * 9.0.4 (including)

References