BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

AnyDesk Linux pre-auth RCE exploit gives root access

Pre-auth RCE exploit AnyPwn published, grants root on AnyDesk Linux; patched in v8.0.3, no CVE

  • Security researchers published AnyPwn, a working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that grants root access without connection approval.
  • AnyDesk patched the flaw in version 8.0.3 in June but described it only as a crash bug, with no CVE or security advisory issued.
  • The exploit targets a heap buffer overflow in AnyDesk’s session protocol and works over direct TCP connections on port 7070, though the same code path may be reachable via relay servers.
  • Administrators should update to at least version 8.0.3; the latest release is 8.1.0, and restricting port 7070 can reduce exposure.

Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. The exploit, called AnyPwn, targets a heap buffer overflow in AnyDesk’s session protocol and was released on GitHub on October 8.

- Advertisement -

AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as “fixed a bug that could lead to a crash” with no CVE assigned and no security advisory. The exploit works only over direct TCP connections on port 7070, and the researchers published the code according to their GitHub repository.

The exploit is probabilistic: the heap layout must place a target object adjacent to the overflowed buffer, or the service crashes instead of executing the attacker’s command. The offsets target a specific build of AnyDesk Linux 8.0.2, and other builds would require different values.

The researchers say the same vulnerable code path is also reachable via AnyDesk‘s relay servers, which the software uses when a direct connection is unavailable. They validated this with a Frida instrumentation trigger but did not demonstrate the full exploit chain over relays.

AnyDesk said in June that the vulnerability is “limited to direct connections on Linux (connections that do not go through our relays).” The researchers announced the flaw on June 22, and AnyDesk acknowledged it the next day, releasing version 8.0.3 with the fix.

- Advertisement -

No CVE has been assigned to the vulnerability as of October 9, and AnyDesk has not issued a formal security advisory. The vulnerability was found by Rick de Jager of the V12 security team using a security code review engine.

A separate AnyDesk heap buffer overflow, CVE-2025-27918, was fixed in version 7.0.0 in April 2025. That vulnerability affected all AnyDesk platforms and involved a different integer overflow mechanism.

AnyDesk was hacked in early 2024 in a separate incident where production systems were breached, leading to certificate revocations and forced password resets. Administrators who cannot update immediately can reduce exposure by restricting access to TCP port 7070.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

CleanSpark Ends Monthly Bitcoin Reports, Cites Data Center Growth

CleanSpark produced 529 BTC in September, averaging 17.64 BTC per day, and holds 13,530...

China doc exposes pig butchering scam border horrors

China released a documentary series exposing pig butchering scams across Southeast AsiaNearly 100,000 law...

Qureshi Slams Drake’s ‘Bunker Mode’ as Crypto Doomerism

Dragonfly managing partner Haseeb Qureshi called Ethereum researcher Justin Drake’s “bunker mode” warning “cryptographic...

CISA Adds 5 Flax Typhoon Exploited Flaws to KEV Catalog

CISA added five vulnerabilities to its Known Exploited Vulnerabilities catalog after China-linked threat actor...

Empire Market co-creator gets 40 years for $430M darknet drug sales

Raheim Hamilton, co-creator of darknet marketplace Empire Market, was sentenced to 40 years in...

Must Read

How to Choose a Cryptocurrency Exchange: Major Risks and Expert Advice

During the bitcoin frenzy, in late 2017, Coinbase, one of the key players in the global cryptocurrency market, stopped trading operations. At a point...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading