"fixed a bug that could lead to a crash," reads AnyDesk's changelog — a terse description that, according to security researchers, understated a flaw that can let an attacker gain root access on affected Linux installs before anyone approves a remote session.
AnyPwn: a working, pre‑auth exploit published on GitHub
On October 8 researchers published a full working exploit called AnyPwn on GitHub that targets a heap buffer overflow in AnyDesk's session protocol and yields root execution on vulnerable Linux hosts. The published code and accompanying analysis show the exploit works over direct TCP connections on port 7070 and was released by the research team after they announced the flaw publicly on June 22.
How the overflow is triggered and what it does
The exploit abuses AnyDesk's mode‑5 stream packet handling. The handler computes an allocation size by adding a 16‑byte header to the declared payload length using 32‑bit arithmetic without checking for overflow. The exploit declares a payload length of 0xFFFFFFF0; adding 0x10 wraps the 32‑bit result to zero, so the allocator reserves a tiny buffer while the object keeps the original large length. A single byte of attacker data then writes past the end of the allocation, corrupting adjacent heap objects. The published code arranges the heap and uses a ROP chain to execute an arbitrary command as root.
The vulnerability was discovered by Rick de Jager of the V12 security team using V12, a security code review engine. The V12 founders previously built security firm Zellic and led the competitive hacking team Perfect Blue.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageVersions, vendor timeline, and disclosure details
The exploit targets AnyDesk Linux build 8.0.2; the researchers imply earlier builds such as 8.0.1 may share the vulnerable code path but have not confirmed exploitation against those versions. AnyDesk released a fix in version 8.0.3 in June and later published 8.1.0; the vendor's changelog entry described the fix only as "fixed a bug that could lead to a crash." AnyDesk acknowledged the researchers' report the day after the June 22 announcement and released 8.0.3 with the remediation.
As of October 9 no CVE has been assigned to the vulnerability and AnyDesk has not published a formal security advisory for the issue. The company's download page no longer lists version 8.0.2, though that build still appears in the changelog; the researchers noted that "the vendor appears to have deleted (?) the 8.0.2 build of AnyDesk upon the release of our poc video."
Attack surface: direct TCP on port 7070 and relay ambiguity
The published exploit functions only over direct TCP connections on port 7070 and is probabilistic: the heap layout must position a target object adjacent to the overflowed buffer; if it does not, the service crashes rather than executing code. The offsets and heap‑spray values embedded in the published code target the specific 8.0.2 build; other builds would require different values.
The researchers say the same vulnerable code path is reachable via AnyDesk's relay servers — the mechanism the product uses when a direct connection cannot be established — and validated reachability of that code path with a Frida instrumentation trigger. They did not, however, demonstrate a complete exploit chain over relays, leaving full exploitability via relays unresolved. AnyDesk told the researchers in June that the vulnerability was "limited to direct connections on Linux (connections that do not go through our relays)" and that Windows and macOS are not affected.
What this means for technologists, enterprises, and adversaries
- Technologists and security teams: Administrators should update AnyDesk Linux to at least version 8.0.3 (the researchers' recommended minimum) or the later 8.1.0 release, and can temporarily reduce exposure by restricting access to TCP port 7070 where an immediate update is not possible.
- Affected enterprises and procurement leaders: Inventory AnyDesk Linux installs and verify builds; the vendor's download page no longer lists 8.0.2 although it appears in the changelog, so teams must confirm current deployments directly rather than rely solely on public listings.
- Adversaries and threat actors: The published proof‑of‑concept lowers the bar for exploitation over direct TCP 7070 on vulnerable Linux hosts; relay‑based exploitation remains an open technical question pending a demonstrated end‑to‑end chain.
The record contains additional context that matters here: a separate AnyDesk heap buffer overflow, CVE‑2025‑27918, was fixed in version 7.0.0 in April 2025 and involved a different mechanism (an integer overflow in user image processing). AnyDesk also experienced a production‑system breach in early 2024 that led to certificate revocations and forced password resets. Those incidents and the current public exploit underscore that administrators must reconcile version inventories, patch status, and exposure to direct TCP connections on port 7070.
Two clear open facts remain: the vendor has not issued a formal security advisory or a CVE as of October 9, and researchers did not demonstrate the exploit end‑to‑end over AnyDesk relays. Until those gaps are closed, the pragmatic step is simple and documented by the researchers: update to 8.0.3 or later, or restrict access to TCP port 7070.




