CVE-2025-27916

7.5

AnyDesk · AnyDesk for Windows, AnyDesk for Android

AnyDesk for Windows before 9.0.6 and Android before 8.0.0 are vulnerable to ID spoofing when connections are established via IP address, allowing for potential data manipulation.

Executive summary

A critical vulnerability in AnyDesk allows unauthenticated attackers to spoof AnyDesk IDs and manipulate connection data, posing a significant risk to remote access integrity.

Vulnerability

The vulnerability exists in the connection handshake process when two clients connect directly via IP address. An unauthenticated attacker can manipulate data packets to spoof the expected AnyDesk ID, effectively performing a man-in-the-middle or impersonation attack.

Business impact

The ability to spoof an AnyDesk ID undermines the core trust model of remote support and management sessions. Successful exploitation could allow unauthorized parties to masquerade as legitimate administrators or support staff, potentially leading to unauthorized system access, data exfiltration, or the deployment of malicious payloads. Given the CVSS score of 7.5, this high-severity flaw requires immediate attention to prevent compromise of remote management infrastructure.

Remediation

Immediate Action: Update all instances of AnyDesk for Windows to version 9.0.6 or later and AnyDesk for Android to version 8.0.0 or later.

Proactive Monitoring: Review AnyDesk connection logs for unexpected IP addresses or anomalous connection patterns during remote support sessions.

Compensating Controls: Restrict AnyDesk direct IP connections via host-based firewalls, requiring all traffic to route through verified AnyDesk relay infrastructure where possible.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations relying on AnyDesk for remote operations must prioritize this update to maintain the integrity of their remote access environment. Because the flaw allows for impersonation without authentication, the risk of exploitation is elevated. Please verify that all endpoints are updated to the specified versions immediately to neutralize the risk of ID spoofing and session manipulation.

More AnyDesk CVEs

Sources