CVE-2025-27917

An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL pointer dereference.
Configurations

Configuration 1 (hide)

cpe:2.3:a:anydesk:anydesk:*:*:*:*:*:windows:*:*

History

08 Dec 2025, 17:16

Type Values Removed Values Added
Summary (en) An issue was discovered in AnyDesk through 9.0.4. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL pointer dereference. (en) An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL pointer dereference.

07 Nov 2025, 18:07

Type Values Removed Values Added
CWE CWE-476
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://anydesk.com/en/changelog/windows - () https://anydesk.com/en/changelog/windows - Release Notes
References () https://dspace.cvut.cz/bitstream/handle/10467/122721/F8-DP-2025-Krejsa-Vojtech-DP_Krejsa_Vojtech_2025.pdf - () https://dspace.cvut.cz/bitstream/handle/10467/122721/F8-DP-2025-Krejsa-Vojtech-DP_Krejsa_Vojtech_2025.pdf - Exploit, Third Party Advisory
CPE cpe:2.3:a:anydesk:anydesk:*:*:*:*:*:windows:*:*
First Time Anydesk anydesk
Anydesk

06 Nov 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-11-06 18:15

Updated : 2025-12-08 17:16


NVD link : CVE-2025-27917

Mitre link : CVE-2025-27917

CVE.ORG link : CVE-2025-27917


JSON object : View

Products Affected

anydesk

  • anydesk
CWE
CWE-476

NULL Pointer Dereference