Public exploit lands for pre-auth AnyDesk Linux flaw that yields root
A working proof-of-concept exploit is now public for a pre-authentication remote code execution bug in AnyDesk for Linux. On a vulnerable host, an attacker can get commands running as root before anyone accepts the incoming connection. AnyDesk fixed the bug in version 8.0.3 back in June. The fix shipped quietly, though: the changelog called it a crash fix, and there is still no CVE or security advisory. Many Linux fleets may never have treated it as urgent.
What happened
- The bug was found by Rick de Jager of the V12 security team using V12's automated code-review engine. The researchers disclosed it on June 22. AnyDesk acknowledged it the next day and shipped 8.0.3 with the fix.
- On October 8 the researchers published a full exploit, dubbed AnyPwn, on GitHub, together with a demo video.
- As of October 9, no CVE had been assigned and AnyDesk had not published a formal security advisory. The 8.0.3 changelog only mentions fixing "a bug that could lead to a crash".
- AnyDesk says the issue is limited to direct (non-relayed) connections on Linux. Windows and macOS are not affected.
How the flaw works (high level)
The bug sits in AnyDesk's session protocol. When the client handles a particular type of stream packet, it adds a small header to an attacker-declared payload length to size a heap buffer, and it does that with 32-bit arithmetic and no overflow check. A crafted length wraps the sum around to a tiny value. The program then allocates a small buffer but still copies data as if the buffer were large, which causes a heap buffer overflow. The public exploit uses this to corrupt adjacent heap objects and run an arbitrary command as root.
Some limits on the public exploit:
- It works over direct TCP connections on port 7070.
- It is probabilistic. The heap layout has to line up, and when it doesn't, the service crashes instead.
- Its offsets are tuned for AnyDesk Linux 8.0.2. Other builds would need different values. The researchers suggest earlier releases such as 8.0.1 may share the vulnerable code, but exploitation of those has not been confirmed.
- The researchers say the same code path is reachable through AnyDesk's relay servers, and they triggered it that way using instrumentation. They did not demonstrate the full exploit chain over relays, so whether it is fully exploitable through relays is still an open question.
This is a different bug from CVE-2025-27918, an integer overflow in AnyDesk's user-image handling that affected all platforms and was fixed in 7.0.0 in April 2025.
Why it matters
- Remote-access tools are high-value targets. AnyDesk is widely used for IT support and is often installed on servers and admin workstations. Pre-auth root on those machines gives an attacker full control without stolen credentials or user interaction.
- Silent fixes get missed. Patch management that keys on CVEs or vendor advisories would not have flagged 8.0.3 as a security update. Linux hosts that drift behind on point releases are likely still exposed.
- Public code lowers the bar. The exploit currently targets one build and is unreliable, but published working code tends to be adapted to other builds quickly.
What to do
- Inventory AnyDesk on Linux. Find every Linux endpoint and server running AnyDesk, including ones installed ad hoc by support staff or vendors.
- Update now. Move to 8.0.3 or later. The current release is 8.1.0. Treat this as a security patch even though there is no CVE.
- Restrict TCP 7070. If you can't update right away, block or tightly limit inbound access to TCP port 7070 (AnyDesk direct connections), especially from the internet.
- Remove what you don't need. Uninstall AnyDesk from servers and machines that don't need unattended remote access, and standardize on one sanctioned remote-access tool.
- Watch for crashes. Since a failed exploit attempt crashes the service, treat unexplained AnyDesk crashes on Linux hosts as a possible signal and investigate them.
- Don't rely on CVE feeds alone. Track vendor changelogs for business-critical remote-access software, and include these tools in your exposure monitoring.
4Tify continuously maps exposed services such as remote-desktop ports across your external attack surface, so you can find and close issues like this one before they're targeted.
Originally reported by The Hacker News.
