Full Report
Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection. AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as "fixed a bug that could lead to a crash," with no CVE assigned and no security
Analysis Summary
# Vulnerability: AnyPwn - AnyDesk Linux Pre-Auth Remote Code Execution
## CVE Details
- **CVE ID**: None assigned (Vendor tracked the fix as a generic bug fix).
- **CVSS Score**: Not officially scored, but estimated **9.8 - 10.0 (Critical)** due to pre-authentication root access.
- **CWE**: CWE-122 (Heap-based Buffer Overflow) / CWE-190 (Integer Overflow).
## Affected Systems
- **Products**: AnyDesk for Linux.
- **Versions**: Version 8.0.2 and likely earlier (e.g., 8.0.1).
- **Configurations**: Systems accepting direct TCP connections or connections via AnyDesk relay servers.
## Vulnerability Description
The flaw exists within the AnyDesk session protocol’s handling of mode-5 stream packets. When calculating the size for a backing allocation, the handler adds a 16-byte header to the attacker-declared payload length using 32-bit arithmetic. By declaring a payload length of `0xFFFFFFF0`, the addition of `0x10` (16) causes an integer overflow, wrapping the result to zero.
This results in a tiny buffer allocation, while the system still expects a massive payload. Subsequent data writes result in a heap buffer overflow, allowing attackers to corrupt adjacent heap objects and utilize a Return-Oriented Programming (ROP) chain to execute arbitrary commands as the **root** user.
## Exploitation
- **Status**: PoC available (Full working exploit titled "AnyPwn" published on GitHub).
- **Complexity**: Medium (Exploit is probabilistic; it requires specific heap layouts and offsets tailored to the specific build/version).
- **Attack Vector**: Network (Port 7070 for direct connections, or via relay servers).
## Impact
- **Confidentiality**: High (Full system access)
- **Integrity**: High (Full system access)
- **Availability**: High (Service crash or system takeover)
## Remediation
### Patches
- **AnyDesk Linux 8.0.3**: Initial patch release (June 2026).
- **AnyDesk Linux 8.1.0**: Latest stable release.
### Workarounds
- **Network Filtering**: Restrict or block access to **TCP port 7070** at the firewall level to prevent direct connection exploits.
- **Access Control**: Disable direct connections in the AnyDesk settings if not strictly required.
## Detection
- **Indicators of Compromise**:
- Unexpected crashes of the AnyDesk service (`anydesk` process).
- Unexplained root-level activity or unauthorized terminal commands originating from the AnyDesk process.
- **Detection methods and tools**:
- Monitor network traffic for unusual large-payload packets directed at port 7070.
- Check system logs for "AnyPwn" related strings or unusual heap corruption errors in the application logs.
## References
- **Vendor Changelog**: [https://anydesk[.]com/en/changelog/linux]
- **PoC Repository**: [https://github[.]com/v12-security/pocs/tree/main/anydesk]
- **Researcher Announcement**: [https://x[.]com/v12sec/status/2069178874118668364]
- **News Source**: [https://thehackernews[.]com/2026/10/researchers-publish-working-exploit-for.html]