
AnyDesk Linux root exploit puts June patch in spotlight
AnyDesk Linux exploit gives attackers root access before connection approval; a June fix is available, but exploitation through relays remains unresolved.
AnyDesk Linux has a publicly available exploit that can give an attacker root access, meaning full administrative control, before anyone accepts a remote desktop connection. The code targets version 8.0.2 of the remote-access software. AnyDesk fixed the underlying flaw in version 8.0.3 in June, but described the change as a crash fix rather than a security correction.
The exploit, named AnyPwn, was published on GitHub on October 8. According to The Hacker News, Rick de Jager of the V12 security team discovered the vulnerability using V12, a security code review engine. V12's founders previously built the security company Zellic and led the competitive hacking team Perfect Blue. The researchers announced the flaw on June 22; AnyDesk acknowledged it the following day and released version 8.0.3 with the correction.
For businesses and IT teams using AnyDesk Linux, the immediate priority is to install version 8.0.3 or later. The source lists 8.1.0 as the latest release. This is a pre-authentication remote code execution vulnerability: an attacker can make the system run instructions without first being authenticated. Waiting to reject an unfamiliar connection is therefore not a substitute for updating. Website owners should check whether their administrators use AnyDesk on Linux systems involved in managing their sites, rather than assume this is a flaw in the website software itself.
What the published exploit proves
The released AnyPwn code works through direct Transmission Control Protocol (TCP) connections on port 7070, a numbered network entry point used by the service. Its built-in memory offsets, the positions used to locate targets inside the program, are specific to AnyDesk Linux 8.0.2. Other builds would need different values. The researchers suggest that earlier releases, including 8.0.1, may contain the same vulnerable code path, but successful exploitation of those releases has not been confirmed.
Success is not guaranteed on every attempt. The exploit depends on the heap, a region of memory where a program stores objects while running, placing a target object next to the buffer being overwritten. If that arrangement is absent, the attempt crashes the service instead of running the attacker's command. That limitation narrows what the demonstration establishes, but does not remove the risk to systems matching its requirements.
A separate question concerns AnyDesk's relay servers, intermediary systems used when computers cannot connect directly. The researchers say they reached the vulnerable code through those relays using a trigger built with Frida, a tool for observing and modifying a running program. They did not demonstrate the complete exploit through a relay. AnyDesk's June statement said the vulnerability affected only direct Linux connections that bypass its relays, and that Windows and macOS were unaffected. The researchers' finding and the vendor's stated scope therefore leave full exploitation through relays unresolved.
Why the memory handling fails
The flaw lies in AnyDesk's session protocol, the rules its software uses to exchange connection data, specifically its mode-5 stream packets. The handler adds a 16-byte header to the declared payload length to determine how much memory to allocate. It performs that addition using 32-bit arithmetic, which has a fixed maximum value, without checking whether the result exceeds that limit.
AnyPwn declares a payload length of 0xFFFFFFF0. Adding the header size, 0x10, makes the 32-bit result wrap around to zero. The program consequently allocates a tiny buffer while retaining the original, much larger length in the associated object. Even a single byte of attacker-supplied data can then go beyond the allocated space. This is a heap buffer overflow, a write outside a reserved memory area that can damage neighbouring objects.
The exploit corrupts fields in those adjacent objects and uses a return-oriented programming (ROP) chain, which combines pieces of existing program instructions, to execute an arbitrary command as root. The important operational distinction is that the demonstrated result is not merely a crash: under the required memory conditions, it is execution with the system's highest privileges.
A fix without a formal advisory
As of October 9, the flaw had no Common Vulnerabilities and Exposures (CVE) identifier, the standard reference used to track publicly disclosed vulnerabilities, and AnyDesk had issued no formal security advisory. Its changelog presented the June correction only as a bug that could cause a crash. That description did not communicate the root-level execution now shown by the published exploit.
AnyDesk's download page no longer lists version 8.0.2, although that release remains in the changelog. The researchers questioned whether its removal followed publication of their proof-of-concept video, which demonstrated the flaw. The source does not establish the reason for the removal, so that suggested connection should not be treated as confirmed.
This issue is distinct from CVE-2025-27918, another AnyDesk heap buffer overflow corrected in version 7.0.0 in April 2025. That earlier vulnerability affected all AnyDesk platforms and involved integer overflow, arithmetic exceeding its permitted range, in user image processing rather than the session protocol. It is also separate from the early-2024 breach of AnyDesk's production systems, which prompted certificate revocations, invalidating digital credentials, and forced password resets.
For organisations reviewing the remote-access software in their IT estate, AEU-I offers security-first IT, infrastructure and consulting services relevant to that work. Administrators unable to update immediately can reduce direct exposure by restricting access to TCP port 7070. Because full relay exploitation remains unresolved, that restriction should be treated as an interim exposure reduction, not a replacement for installing the fixed AnyDesk Linux release.
Si të Mbroheni
- Check the installed AnyDesk version on your Linux computers, or ask your IT provider to check it for you.
- Update AnyDesk on Linux to version 8.0.3 or later using the official AnyDesk download source.
- If an update must wait, ask your IT provider to restrict access to AnyDesk's direct connection entry point, TCP port 7070.
- Do not rely on rejecting unexpected connection requests to stop this flaw, because it can be exploited before you approve a connection.
Dobësitë & Zgjidhjet
- CVE-2025-27918 A separate AnyDesk user image processing heap buffer overflow affected all platforms and was fixed in version 7.0.0 in April 2025. Shiko zgjidhjen & detajet →
Termat e Shpjeguar
- root access The highest level of control over a Linux computer, allowing changes throughout the system.
- pre-authentication remote code execution A weakness that lets someone make another computer run instructions without first proving they are an authorised user.
- heap buffer overflow A fault where a program writes beyond a reserved area of memory and can damage nearby data.
- relay servers Computers that pass connection data between devices that cannot communicate directly.
- return-oriented programming (ROP) chain An attack technique that links existing pieces of a program to carry out the attacker's instructions.
- Common Vulnerabilities and Exposures (CVE) A system of public identifiers that helps people track and distinguish known security flaws.