High severity8.2NVD Advisory· Published Nov 6, 2025· Updated Jun 17, 2026
CVE-2025-27919
CVE-2025-27919
Description
An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from the counterparty. Consequently, the attacker can later connect without this counterparty confirmation.
Affected products
3Patches
Vulnerability mechanics
References
2- dspace.cvut.cz/bitstream/handle/10467/122721/F8-DP-2025-Krejsa-Vojtech-DP_Krejsa_Vojtech_2025.pdfnvdExploitThird Party Advisory
- anydesk.com/en/changelog/windowsnvdRelease Notes
News mentions
0No linked articles in our index yet.