CVE-2025-27916: High severity AnyDesk AnyDesk vulnerability
An issue was discovered in AnyDesk for Windows before 9.0.6 and AnyDesk for Android before 8.0.0. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof the AnyDesk ID.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27916?
CVE-2025-27916 is considered a high severity vulnerability due to its potential impact on data integrity and client authentication.
How do I fix CVE-2025-27916?
To fix CVE-2025-27916, update AnyDesk to the latest version beyond 9.0.4 where the vulnerability has been patched.
What type of vulnerability is CVE-2025-27916?
CVE-2025-27916 is a data manipulation and spoofing vulnerability that affects client connections in AnyDesk.
What software versions are affected by CVE-2025-27916?
AnyDesk versions up to and including 9.0.4 are affected by CVE-2025-27916.
How can attackers exploit CVE-2025-27916?
Attackers can exploit CVE-2025-27916 by establishing a connection via an IP address and manipulating the transmitted data to spoof the AnyDesk ID.