CVE-2025-27917
7.5AnyDesk · AnyDesk
AnyDesk is vulnerable to a remote denial of service attack due to improper deserialization, causing memory allocation failures and NULL pointer dereferences.
Executive summary
A remote denial of service vulnerability in AnyDesk allows unauthenticated attackers to crash the application across multiple platforms.
Vulnerability
This vulnerability involves incorrect deserialization of data, which triggers a failed memory allocation and subsequent NULL pointer dereference. The flaw is exploitable by unauthenticated remote attackers.
Business impact
The vulnerability carries a CVSS score of 7.5, indicating a high severity risk. Successful exploitation results in a complete denial of service, rendering remote support and administrative access unavailable. This disruption can significantly impact IT operations, incident response capabilities, and general business productivity.
Remediation
Immediate Action: Update AnyDesk software to the latest versions (Windows 9.0.5+, macOS 9.0.1+, Linux 7.0.0+, iOS 7.1.2+, or Android 8.0.0+) immediately to resolve the deserialization flaw.
Proactive Monitoring: Monitor system logs for unexpected application crashes or service restarts that may indicate attempted exploitation of this memory-related flaw.
Compensating Controls: Restrict network access to AnyDesk management ports via firewall rules to ensure that only authorized IP ranges can communicate with the application.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the high CVSS score and the existence of proof-of-concept material, organizations must prioritize patching their AnyDesk deployments. Failure to update leaves remote management infrastructure vulnerable to service disruption, which may be leveraged to impede security operations or organizational agility.