Working Exploit Published for Pre-Auth AnyDesk Linux Root Access Vulnerability
Researchers have released a working exploit for a critical AnyDesk Linux vulnerability that allows attackers to gain root access remotely without user interaction.

Security researchers have made public a fully functional exploit for a pre-authentication remote code execution (RCE) vulnerability affecting AnyDesk on Linux systems. This flaw, dubbed AnyPwn, enables attackers to achieve root-level privileges on a target machine without requiring any user approval or interaction, posing a significant risk to organizations relying on the remote desktop software.
AnyDesk addressed the vulnerability in version 8.0.3, released in June. However, the company's release notes initially described the fix merely as "fixed a bug that could lead to a crash," notably omitting any mention of a security advisory or a Common Vulnerabilities and Exposures (CVE) identifier. This lack of transparency initially downplayed the severity of the issue.
The AnyPwn exploit targets a heap buffer overflow within AnyDesk's session protocol. The exploit code, released on GitHub on October 8, demonstrates how an attacker can leverage this overflow to execute arbitrary commands. While the exploit is probabilistic and requires specific heap layouts for successful execution, it is effective against specific builds of AnyDesk Linux, such as version 8.0.2.
While the published exploit primarily targets direct TCP connections on port 7070, the researchers indicated that the vulnerable code path is also accessible through AnyDesk's relay servers. These servers are used when direct connections are not feasible. Although the full exploit chain over relays was not demonstrated, the researchers confirmed its reachability using instrumentation tools, suggesting a broader attack surface than initially apparent.
AnyDesk stated in June that the vulnerability was limited to direct Linux connections, asserting that Windows and macOS were unaffected. The exploit specifically targets AnyDesk Linux 8.0.2, with researchers suggesting that earlier versions might also be vulnerable, though exploitation has not been confirmed for them. The vendor has since removed version 8.0.2 from its download page, making it harder to obtain.
The technical mechanism behind the flaw involves AnyDesk's session protocol handling mode-5 stream packets. The software calculates the size of its buffer allocation using 32-bit arithmetic without proper overflow checking. By providing a payload length of 0xFFFFFFF0, the addition of a 16-byte header causes a 32-bit integer overflow, resulting in a near-zero allocation size. Subsequent data writes then exceed the allocated buffer, corrupting adjacent heap objects and enabling the execution of a ROP chain to achieve root command execution.
Administrators are strongly advised to update their AnyDesk Linux installations to version 8.0.3 or later. For those unable to update immediately, restricting access to TCP port 7070 can serve as a temporary mitigation. The full extent of exploitability over relay connections remains an area requiring further investigation.
The vulnerability was discovered by Rick de Jager of the V12 security team using their V12 security code review engine. This incident follows a separate breach of AnyDesk's production systems in early 2024, which led to certificate revocations and forced password resets, highlighting ongoing security challenges for the company.