CVE-2025-27918: Integer Overflow
An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. It has an integer overflow and resultant heap-based buffer overflow via a UDP packet during processing of an Identity user image within the Discovery feature, or when establishing a connection between any two clients.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27918?
CVE-2025-27918 is classified as a high-severity vulnerability due to its potential for exploitation leading to a heap-based buffer overflow.
How do I fix CVE-2025-27918?
To mitigate CVE-2025-27918, update AnyDesk to version 9.0.0 or later, which contains the necessary patches.
What causes CVE-2025-27918?
CVE-2025-27918 is caused by an integer overflow that results in a heap-based buffer overflow when processing user images in the Discovery feature.
Which versions of AnyDesk are affected by CVE-2025-27918?
CVE-2025-27918 affects all versions of AnyDesk prior to 9.0.0.
What actions should users take regarding CVE-2025-27918?
Users should immediately update their AnyDesk application to version 9.0.0 or later to protect against CVE-2025-27918.