Critical AnyDesk Linux Vulnerability Exposed: Working Root-Level Exploit Published

A dangerous flaw in AnyDesk for Linux—allowing root-level access without user interaction—has been publicly addressed after researchers released a working exploit. The vulnerability, dubbed “AnyPwn,” involves a heap buffer overflow issue in AnyDesk’s session protocol. Administrators are urged to upgrade to version 8.0.3 or newer, with the current released version being 8.1.0, to protect against potential attacks.

How the Vulnerability Works

The issue springs from how AnyDesk handles mode-5 stream packets. The software adds a fixed-size 16-byte header to the declared payload length using 32-bit arithmetic—without checking for overflow. When an attacker sends a payload length of 0xFFFFFFF0, adding the header wraps the calculation back to zero. This results in allocating an almost non-existent buffer while still treating the length as large, enabling data writes that spill over the buffer. Adjacent heap objects are overwritten, and with a ROP (Return-Oriented Programming) chain, arbitrary commands can be executed as root.

This flaw specifically affects AnyDesk Linux version 8.0.2. Earlier versions may share the vulnerable code path, but there’s no proof they’re exploitable in the same way. The researchers used a particular build to target exact memory offsets; other builds might require adjustments.

Scope, Exposure, and Mitigation Advice

AnyPwn works when attacking over direct TCP connections using port 7070. While relay servers used by AnyDesk may also expose the same flawed code path, the research team only partially triggered that path using Frida instrumentation—not fully demonstrating remote execution over relays. AnyDesk confirmed that Windows and macOS are not affected; the flaw is confined to Linux direct connections.

AnyDesk rolled out a patch in version 8.0.3 in June to address the issue, but the accompanying changelog vaguely noted only a crash bug fix. No CVE number nor formal security advisory has been published as of October 9, 2026. The company’s download page no longer shows version 8.0.2, although it is still mentioned in published change logs.

Until systems are updated, administrators should block external access to TCP port 7070 to limit risk. It’s unclear if the exploit can be mounted via relay servers, though that possibility remains under investigation.

Discovery and Background

The issue was discovered by Rick de Jager of the V12 security team, which operates the V12 code review engine. V12’s founders were previously part of security firm Zellic and the competitive hacking collective Perfect Blue.

This isn’t the first time AnyDesk has been hit by vulnerabilities. A different buffer overflow (CVE-2025-27918) was patched in April 2025; that weakness was platform-wide and stemmed from integer overflow during user image processing—distinct from the session protocol flaw exploited by AnyPwn. Notably, AnyDesk also suffered a breach in early 2024 that resulted in revoked certificates and forced password resets.

Both the discovery announcement and upstream acknowledgment occurred on June 22–23, 2026. The official fix followed in version 8.0.3.

======

The AnyPwn exploit represents a serious concern for AnyDesk users on Linux. Without a formal CVE or advisory, it could be underestimated. Updating to the fixed version is non-negotiable. Moving forward, developers and security teams should demand more transparency, faster fixes, and clear advisories when critical vulnerabilities like this emerge—especially when root access is on the line. Watch for security patches accompanied by logs, advisories, and verifiable remediation proof.