Heap-based Buffer Overflow in AnyDesk's Identity User Image Processing
CVE-2025-27918
9.8CRITICAL
What is CVE-2025-27918?
An issue has been identified in AnyDesk prior to version 9.0.0 where an integer overflow occurs, leading to a heap-based buffer overflow. This vulnerability can be exploited through malicious UDP packets, particularly during the processing of user identity images within the Discovery feature or while establishing connections between clients. This flaw poses significant risks, allowing potential attackers to manipulate memory and execute arbitrary code.