📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Patch & vulnerability status

AnyDesk MacOS 8.0.1

Latest tracked version 8.0.1. Release status, tracked CVEs, and automated cross-platform patching for AnyDesk MacOS.

PlatformLatest versionCVEs trackedLast checked
Windows8.0.1192024-05-13

Known vulnerabilities (CVEs) in AnyDesk MacOS

Lavawall tracks 19 published CVEs affecting AnyDesk MacOS, and deploys the versions that fix them automatically across your fleet.

CVEPublishedSeverityDetailsVector
CVE-2026-156822026-07-13 22:16:46MEDIUM (6)AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Send Support Information feature. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26645.LOCAL
CVE-2026-156812026-07-13 22:16:46MEDIUM (6)AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service condition on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of screen recording files. By creating a junction, an attacker can abuse the service to create arbitrary files. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-26591.LOCAL
CVE-2025-279192025-11-06 18:15:41HIGH (8)An issue was discovered in AnyDesk through 9.0.4. A remotely connected user with the "Control my device" permission can manipulate remote AnyDesk settings and create a password for the Full Access profile without needing confirmation from the counterparty. Consequently, the attacker can later connect without this counterparty confirmation.NETWORK
CVE-2025-279182025-11-06 18:15:41CRITICAL (10)An issue was discovered in AnyDesk for Windows before 9.0.5, AnyDesk for macOS before 9.0.1, AnyDesk for Linux before 7.0.0, AnyDesk for iOS before 7.1.2, and AnyDesk for Android before 8.0.0. It has an integer overflow and resultant heap-based buffer overflow via a UDP packet during processing of an Identity user image within the Discovery feature, or when establishing a connection between any two clients.NETWORK
CVE-2025-279172025-11-06 18:15:41HIGH (8)An issue was discovered in AnyDesk through 9.0.4. Remote Denial of Service can occur because of incorrect deserialization that results in failed memory allocation and a NULL pointer dereference.NETWORK
CVE-2025-279162025-11-06 18:15:40HIGH (8)An issue was discovered in AnyDesk through 9.0.4. When the connection between two clients is established via an IP address, it is possible to manipulate the data and spoof the AnyDesk ID.NETWORK
CVE-2024-127542024-12-30 17:15:07HIGH (8)AnyDesk Link Following Information Disclosure Vulnerability. This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of background images. By creating a junction, an attacker can abuse the service to read arbitrary files. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-23940.NETWORK
CVE-2023-265092023-07-03 15:15:10HIGH (8)AnyDesk 7.0.8 allows remote Denial of Service.NETWORK
CVE-2022-324502022-07-18 13:15:10HIGH (7)AnyDesk 7.0.9 allows a local user to gain SYSTEM privileges via a symbolic link because the user can write to their own %APPDATA% folder (used for ad.trace and chat) but the product runs as SYSTEM when writing chat-room data there.LOCAL
CVE-2021-444262022-09-12 21:15:09HIGH (9)An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.5. An upload of an arbitrary file to a victim's local ~/Downloads/ directory is possible if the victim is using the AnyDesk Windows client to connect to a remote machine, if an attacker is also connected remotely with AnyDesk to the same remote machine. The upload is done without any approval or action taken by the victim.NETWORK
CVE-2021-444252022-09-12 21:15:09MEDIUM (7)An issue was discovered in AnyDesk before 6.2.6 and 6.3.x before 6.3.3. An unnecessarily open listening port on a machine in the LAN of an attacker, opened by the Anydesk Windows client when using the tunneling feature, allows the attacker unauthorized access to the local machine's AnyDesk tunneling protocol stack (and also to any remote destination machine software that is listening to the AnyDesk tunneled port).ADJACENT_NETWORK
CVE-2021-408542021-10-14 05:15:08HIGH (8)AnyDesk before 6.2.6 and 6.3.x before 6.3.3 allows a local user to obtain administrator privileges by using the Open Chat Log feature to launch a privileged Notepad process that can launch other applications.LOCAL
CVE-2020-354832021-01-11 15:15:13HIGH (8)AnyDesk before 6.1.0 on Windows, when run in portable mode on a system where the attacker has write access to the application directory, allows this attacker to compromise a local user account via a read-only setting for a Trojan horse gcapi.dll file.LOCAL
CVE-2020-276142020-12-09 00:15:13HIGH (8)AnyDesk for macOS versions 6.0.2 and older have a vulnerability in the XPC interface that does not properly validate client requests and allows local privilege escalation.LOCAL
CVE-2020-131602020-06-09 17:15:10CRITICAL (10)AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.NETWORK
CVE-2019-252612026-02-03 15:16:10HIGH (9)AnyDesk 5.4.0 contains an unquoted service path vulnerability in its Windows service configuration that allows local attackers to potentially inject malicious executables. Attackers can exploit the unquoted binary path to place malicious files in service executable locations, potentially gaining elevated system privileges.LOCAL
CVE-2018-131022018-07-03 16:29:00MEDIUM (7)AnyDesk before "12.06.2018 - 4.1.3" on Windows 7 SP1 has a DLL preloading vulnerability.NETWORK
CVE-2017-143972017-09-12 21:29:00HIGH (8)AnyDesk before 3.6.1 on Windows has a DLL injection vulnerability.NETWORK
CVE-2016-200942026-06-19 15:16:33HIGH (9)AnyDesk 2.5.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service installation. Attackers can insert malicious executables in the system root path that execute with elevated privileges during application startup or system reboot.LOCAL

Why keeping AnyDesk MacOS patched matters

Unpatched third-party applications are one of the most common ways attackers get in: 57% of breached MSP clients and 32% of ransomware cases trace back to a missing patch. Every AnyDesk MacOS release that fixes a security bug is public, so attackers see it too, and an out-of-date install becomes a documented way in. Tracking the installed version on every machine and closing the gap quickly is what turns a disclosed CVE into a non-event.

How Lavawall® patches AnyDesk MacOS

Lavawall® watches AnyDesk MacOS releases and CVEs continuously, ranks each update by risk, and deploys it across your whole fleet, Windows, macOS, and Linux, from a single agent, independently of your RMM. You get one place to see which machines are behind on AnyDesk MacOS, one policy to bring them current, and timestamped evidence for audits.

Frequently asked questions

What is the latest version of AnyDesk MacOS?
Lavawall tracks AnyDesk MacOS at version 8.0.1 (last checked 2024-05-13). New releases are monitored continuously and can be deployed automatically across your fleet.
Does AnyDesk MacOS have known security vulnerabilities (CVEs)?
Lavawall tracks 19 CVEs for AnyDesk MacOS and remediates them automatically as part of patching.
How do I patch AnyDesk MacOS automatically?
Deploy the Lavawall® agent and AnyDesk MacOS updates are applied automatically across Windows, macOS, and Linux, risk-ranked and reported, independently of your RMM.

Lavawall® monitors releases and CVEs for AnyDesk MacOS through public information and proprietary statistical analysis, and can patch it automatically across your fleet.