A working proof of concept has been released for a serious vulnerability in AnyDesk for Linux that could allow remote attackers to execute commands with root privileges without authentication or user interaction.
The vulnerability, known as AnyPwn, affects AnyDesk Linux 8.0.2 and was fixed in version 8.0.3. Organizations using AnyDesk on Linux systems should prioritize the update and check whether the service is accessible from untrusted networks.
The flaw was discovered by Rick de Jager from the V12 security team using the V12 AI-powered security testing platform. It was initially disclosed in June as a pre-authentication, zero-click remote code execution vulnerability caused by a heap buffer overflow.
AnyDesk acknowledged the report and released version 8.0.3 shortly afterward. The public exploit was released on October 8, increasing the risk for systems that have not yet been updated.
How the AnyDesk Linux Vulnerability Works
The vulnerability is located in AnyDesk’s session protocol, which handles information exchanged when remote clients connect to the service.
In the affected version, a packet-processing function does not properly validate a value that tells the application how much data is expected. The application then performs a calculation using this value before allocating memory.
A specially crafted value can cause the calculation to overflow. As a result, AnyDesk may allocate a much smaller memory area than expected while continuing to process the data as though a much larger space had been reserved.
This can result in an out-of-bounds memory write.
In simple terms, an attacker can send specially crafted network data that causes AnyDesk to write beyond the memory area it was supposed to use. Under the right conditions, this can corrupt memory and change how the application executes code.
Researchers demonstrated that the flaw could be used to execute an attacker-controlled command through the AnyDesk service.
The impact is particularly serious because the AnyDesk Linux service normally runs with root privileges. Successful exploitation could therefore give an attacker extensive control over the affected system, including access to files, processes, accounts, and security settings.
The published exploit targets AnyDesk Linux 8.0.2 running in service mode on x86_64 systems and connects directly through TCP port 7070.
However, exploitation is not guaranteed in every situation. The exploit depends on a specific memory layout, and an unsuccessful attempt may simply cause the AnyDesk service to crash.
The researchers also investigated whether the vulnerable code could be reached through AnyDesk relay connections. While they were able to reach the relevant code path during testing, they did not demonstrate the complete root-code-execution attack through a relay. Direct exposure of TCP port 7070 therefore remains the clearest confirmed risk.
Update AnyDesk and Restrict Port 7070
Administrators should identify Linux systems running AnyDesk 8.0.2 or earlier affected builds and upgrade them to version 8.0.3 or later.
If an immediate update is not possible, organizations should reduce exposure by restricting access to TCP port 7070 using firewalls, VPN controls, and cloud security groups.
Security teams should also review affected systems for signs of suspicious activity, including:
- Unexpected root-level processes
- Unusual outbound network connections
- Suspicious AnyDesk service activity
- Unexpected changes to system files or accounts
- Connections to exposed TCP/7070 services
AnyDesk’s Linux changelog records the fix, although the original entry described the issue as a problem that could cause a crash rather than detailing its security impact.
The release of a public exploit makes this vulnerability more important for organizations that have not yet patched their Linux systems.
The key takeaway: AnyDesk is a trusted remote-access tool, but an exposed and vulnerable installation can become a direct entry point for attackers. Update to 8.0.3 or later and restrict unnecessary network access to the service.