Vulnerabilities
AnyPwn: public root exploit for AnyDesk on Linux
A working exploit for a pre-auth heap overflow in AnyDesk Linux 8.0.2 is now on GitHub. How it works, who is exposed, and how to fix and check hosts.
A working exploit for AnyDesk on Linux went up on GitHub on October 8. Called AnyPwn, it targets a heap buffer overflow in AnyDesk's session protocol and, according to the researchers, runs commands as root on AnyDesk Linux 8.0.2 before anyone approves the incoming connection. No password, no click on "Accept", and no user at the keyboard is needed.
The fix shipped in June in version 8.0.3, but AnyDesk's changelog called it only "a bug that could lead to a crash". As of October 9 there was no CVE and no security advisory, so vulnerability scanners that match on CVE IDs will not flag an unpatched host. If you run AnyDesk on Linux servers, support desktops or kiosks and have not moved them to 8.0.3 or later, they now face a public exploit. AnyDesk says Windows and macOS are not affected.
Who is exposed
The published exploit works over direct connections, where the client reaches the Linux host on TCP port 7070 instead of going through AnyDesk's relay servers. AnyDesk told the researchers in June that the issue is "limited to direct connections on Linux (connections that do not go through our relays)". Any 8.0.2 host whose port 7070 can be reached from the internet, a guest network or a broad internal range is the first priority.
The relay question is not settled. The researchers used Frida, a tool that instruments a running process, to show that the vulnerable code path can also be reached through a relayed connection, though they did not demonstrate a full exploit chain that way. AnyDesk has not answered that point directly. Treat relay-only hosts as at risk until they are patched.
The public code fits 8.0.2 on 64-bit x86 only. The researchers suggest earlier 8.x builds such as 8.0.1 may share the same code, but that has not been confirmed, so assume every Linux build before 8.0.3 is vulnerable.
How it works
AnyDesk exchanges session data in typed packets, and the flaw is in the handler for one packet type the researchers call a mode-5 stream packet. The packet carries a length field that says how large its payload is, and the handler uses that figure to work out how much memory to reserve for it.
The problem is that the length field is attacker-controlled and the size calculation is done in 32-bit arithmetic with no sanity check. A declared length near the 32-bit ceiling makes the computed size wrap around to a very small number. The service then reserves a buffer far smaller than the data it goes on to copy in, and the extra bytes spill past the end of that buffer into neighbouring heap memory. This class of bug is a heap buffer overflow: writing beyond the space that was actually allocated.
Those neighbouring bytes are not free space. They hold other live objects the service is using, including pointers it will follow later. By corrupting them, the overflow lets an attacker steer the program's control flow and, in the researchers' demonstration, run a command. Because the AnyDesk service on Linux runs as root, that command runs as root too. The handler processes the packet before the session is approved, which is why no user interaction is required and why this counts as a pre-authentication flaw.
The exploit is probabilistic. It depends on the right objects sitting next to the overflowed buffer in memory, and when the layout is wrong the service crashes instead of being taken over. A crash is still a denial of service, and a repeated crash loop on the AnyDesk process is one of the clearer signs that someone is trying.
What attackers are doing
There are no reports of exploitation in the wild. What changed on October 8 is that a complete, working proof of concept is now public, so the barrier to using the bug has dropped from "find and weaponise an unannounced flaw" to "download and run".
The flaw was found by Rick de Jager of the V12 security team, using V12, an AI-assisted code review platform, and disclosed publicly on June 22. AnyDesk acknowledged the report the following day and shipped 8.0.3 within the same month. The researchers noted that AnyDesk's download page no longer lists 8.0.2, though the changelog still mentions it, which suggests the vendor pulled the vulnerable build. The current release is 8.1.0.
This is a different bug from CVE-2025-27918, an earlier AnyDesk heap overflow fixed in version 7.0.0 in April 2025. That one came from an integer overflow in user image processing and affected all platforms. The AnyPwn flaw is specific to the Linux session protocol and has no CVE at the time of writing.
What to do
1. Update to a fixed build
Move every Linux host to AnyDesk 8.0.3 or later; 8.1.0 is current and the safer target. This is the only real fix. Include the hosts that are easy to forget: jump boxes, lab machines, digital signage and kiosks, and any image or container that bakes AnyDesk in. Windows and macOS installs are not affected by this flaw, so you can scope the push to Linux.
2. If you cannot patch today
Block inbound TCP 7070 to AnyDesk Linux hosts from anything that does not need it, at the host firewall and at the network edge, VPN and cloud security group. Allowing only known support-team source addresses cuts the set of machines that can send the malformed packet over a direct connection. Because the researchers reached the same code over a relay, treat this as a stopgap that reduces exposure, not a fix, and keep hosts off the open internet entirely.
3. Check whether you were hit
- Look at the AnyDesk service logs and the system journal for the AnyDesk process crashing and restarting repeatedly. A failed exploit attempt crashes the service, so a crash loop that lines up with connections to port 7070 is a strong signal.
- Check for connections to TCP 7070 from source addresses you do not recognise, in host firewall logs, netflow or your edge firewall.
- Look for child processes spawned by the AnyDesk service that it would never start itself, such as a shell, an interpreter or a network tool. The service running as root means any such child also runs as root.
4. If you find signs of compromise
Assume full control of the host. A root-level foothold can change anything on the machine, including the logs you would use to investigate, so rebuild the host from a known-good image rather than cleaning it in place. Rotate every credential and key that lived on it or that it could reach: SSH keys, service account passwords, API tokens and any AnyDesk configuration or unattended-access password set on that machine. Review what the host could talk to on the internal network and check those systems too.
The wider lesson
A fix that ships with no CVE and a changelog line about "a crash" is easy to skip. Patch decisions often ride on severity ratings and advisory text, and this one had neither, so many Linux fleets will have stayed on 8.0.2 for four months without a reason to hurry. Remote access tools deserve the same patch discipline as anything else listening on the network: track their versions, read vendor changelogs as well as CVE feeds, and keep their listening ports off untrusted networks by default. A changelog line about a crash can be the only public notice a pre-auth root bug ever gets.
Our network penetration testing checks which remote access and management services can be reached from user, guest and internet-facing networks, and our attack surface management work keeps that inventory current as the fleet changes. Open the chat and Yaali, our AI agent, will pass your question to the engineer who would do the work.
Sources: The Hacker News, Cybersecurity News, The CyberSec Guru, Hunter Strategy.