Vulnerability Description
An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from the counterparty. Consequently, the attacker can later connect without this counterparty confirmation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Anydesk | Anydesk | <= 9.0.4 |
Related Weaknesses (CWE)
References
- https://anydesk.com/en/changelog/windowsRelease Notes
- https://dspace.cvut.cz/bitstream/handle/10467/122721/F8-DP-2025-Krejsa-Vojtech-DExploitThird Party Advisory
FAQ
What is CVE-2025-27919?
CVE-2025-27919 is a vulnerability with a CVSS score of 8.2 (HIGH). An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access pro...
How severe is CVE-2025-27919?
CVE-2025-27919 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-27919?
Check the references section above for vendor advisories and patch information. Affected products include: Anydesk Anydesk.