Working exploit released for pre-auth AnyDesk Linux flaw that grants root access
Researchers have published AnyPwn, an exploit for a heap overflow in AnyDesk for Linux that can run commands as root before a connection is approved. Version 8.0.3 fixes it.
At a glance
- The exploit targets AnyDesk Linux build 8.0.2 over direct TCP connections on port 7070.
- The bug was fixed in 8.0.3 in June, but no CVE or security advisory has been issued.
- AnyDesk says Windows and macOS are not affected.
- No in-the-wild exploitation has been reported.
Security researchers have published a working exploit for a pre-authentication heap overflow in AnyDesk for Linux that can let a remote attacker run commands as root before a user approves an incoming connection, The Hacker News reported. The flaw was quietly fixed in AnyDesk 8.0.3 in June 2026, but it has no CVE identifier or formal security advisory, which means many administrators may not know that older Linux installations are at risk.
What happened
According to The Hacker News, Rick de Jager of the V12 security team found the vulnerability using V12's security code review engine and released an exploit named AnyPwn on GitHub on October 8. The researchers first announced the flaw on June 22, and AnyDesk acknowledged it the next day.
AnyDesk told the researchers that the issue is "limited to direct connections on Linux" and that Windows and macOS versions are not affected, The Hacker News reported. The vendor's changelog describes the fix only as "fixed a bug that could lead to a crash." The researchers also said build 8.0.2 no longer appears on the download page, although it is still listed in the changelog.
Technical details
The Hacker News reported that the bug lies in AnyDesk's session protocol handling. When processing a message, the code adds a 16-byte header to an attacker-declared payload length using 32-bit arithmetic without an overflow check. A crafted length causes the value to wrap around, producing a very small allocation, so attacker-supplied data is written past the end of the buffer and corrupts neighboring heap objects.
The published exploit targets build 8.0.2 and relies on direct TCP connections to port 7070. It is probabilistic: if the target object is not placed next to the overflowed buffer, the service crashes rather than executing code. The researchers suggested earlier builds such as 8.0.1 may share the vulnerable code, but this has not been confirmed. They also said relay connections reach the same vulnerable code path, but they did not demonstrate a full exploit over AnyDesk relays.
Who is affected
Linux systems running AnyDesk versions earlier than 8.0.3 that accept direct connections on TCP port 7070 are the most exposed. The Hacker News said no exploitation in the wild has been reported so far, but the public availability of exploit code lowers the bar for attackers targeting remote access tools.
What to do
Administrators should update AnyDesk on Linux to at least 8.0.3; the latest release is 8.1.0. If an immediate update is not possible, access to TCP port 7070 should be restricted with a firewall. Because no CVE has been assigned, vulnerability scanners may not flag affected installations, so teams should check AnyDesk versions on Linux hosts manually.
Sources
This story is based on the sources listed above. Always check the vendor’s official advisory before acting on critical systems.



