- Security researchers published AnyPwn, a working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that grants root access without connection approval.
- AnyDesk patched the flaw in version 8.0.3 in June but described it only as a crash bug, with no CVE or security advisory issued.
- The exploit targets a heap buffer overflow in AnyDesk’s session protocol and works over direct TCP connections on port 7070, though the same code path may be reachable via relay servers.
- Administrators should update to at least version 8.0.3; the latest release is 8.1.0, and restricting port 7070 can reduce exposure.
Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. The exploit, called AnyPwn, targets a heap buffer overflow in AnyDesk’s session protocol and was released on GitHub on October 8.
AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as “fixed a bug that could lead to a crash” with no CVE assigned and no security advisory. The exploit works only over direct TCP connections on port 7070, and the researchers published the code according to their GitHub repository.
The exploit is probabilistic: the heap layout must place a target object adjacent to the overflowed buffer, or the service crashes instead of executing the attacker’s command. The offsets target a specific build of AnyDesk Linux 8.0.2, and other builds would require different values.
The researchers say the same vulnerable code path is also reachable via AnyDesk‘s relay servers, which the software uses when a direct connection is unavailable. They validated this with a Frida instrumentation trigger but did not demonstrate the full exploit chain over relays.
AnyDesk said in June that the vulnerability is “limited to direct connections on Linux (connections that do not go through our relays).” The researchers announced the flaw on June 22, and AnyDesk acknowledged it the next day, releasing version 8.0.3 with the fix.
No CVE has been assigned to the vulnerability as of October 9, and AnyDesk has not issued a formal security advisory. The vulnerability was found by Rick de Jager of the V12 security team using a security code review engine.
A separate AnyDesk heap buffer overflow, CVE-2025-27918, was fixed in version 7.0.0 in April 2025. That vulnerability affected all AnyDesk platforms and involved a different integer overflow mechanism.
AnyDesk was hacked in early 2024 in a separate incident where production systems were breached, leading to certificate revocations and forced password resets. Administrators who cannot update immediately can reduce exposure by restricting access to TCP port 7070.
✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.
