AnyDesk Linux pre-auth RCE exploit gives root access

Security researchers have released a working exploit for a critical pre-authentication remote code execution flaw in AnyDesk for Linux that allows an attacker to gain root access on a target system without any user interaction or session approval.[1][2][8] The exploit, dubbed AnyPwn, targets a bug that AnyDesk quietly fixed in version 8.0.3 in June, describing it only as “fixed a bug that could lead to a crash” in the changelog, with no CVE identifier or formal security advisory attached.[1][2]

The vulnerability is a heap-based buffer overflow in AnyDesk’s session protocol implementation, reachable before authentication and exploitable over direct TCP connections on port 7070.[1][2][8] According to the researchers, a carefully crafted network packet can corrupt adjacent heap objects and trigger a return-oriented programming (ROP) chain that executes arbitrary commands with root privileges on the Linux host.[1][2] The exploit is probabilistic: if the heap layout does not place a suitable object next to the overflowed buffer, the AnyDesk service will simply crash instead of running the attacker’s payload, but repeated attempts can eventually succeed.[1][2]

The issue first came to light in late June when vulnerability researchers at V12, via the Ransomware Task Force ISAC, disclosed that they had identified a critical heap buffer overflow in AnyDesk enabling zero-click, unauthenticated remote code execution on Linux.[8] In that early statement, AnyDesk said the impact was limited to direct connections on Linux that do not traverse its relay infrastructure and stressed that Windows and macOS clients were not affected, adding that it had found no evidence of exploitation against its infrastructure or customer environments at the time.[8] A patch was promised within 48 hours and ultimately shipped as part of AnyDesk 8.0.3, but the fix was not framed as a security update and no CVE has been registered for the flaw as of October 9.[1][2]

AnyDesk has a prior history of serious remote code execution bugs in its Linux client, including CVE-2020-13160, a format-string vulnerability affecting AnyDesk for Linux and FreeBSD before version 5.5.3 that also allowed RCE and carries a CVSS v3.1 score of 9.8 (Critical).[11] The newly exploited pre-auth heap overflow appears to be a distinct issue in newer code and is not covered by that older CVE, underscoring gaps in formal vulnerability tracking for the current flaw.[1][11] Public CVE aggregation services and vendor-specific lists still show no entry for a Linux pre-auth RCE in AnyDesk 8.x, reinforcing that this bug remains unofficially documented despite its severity.[5][6]

The AnyPwn exploit code was published on GitHub on October 8, significantly lowering the barrier for threat actors to weaponize the flaw against unpatched Linux systems running AnyDesk.[1][2] Remote desktop tools like AnyDesk are frequently abused in ransomware and intrusion campaigns, where attackers install them to maintain persistent, interactive access to compromised hosts.[13] With a working, pre-auth exploit now available, adversaries no longer need valid credentials or social engineering to gain control over exposed AnyDesk Linux instances, making direct TCP access on port 7070 a high-value target for scanning and opportunistic attacks.[1][2][8]

Defenders should treat this vulnerability as a critical remote code execution risk and prioritize upgrading AnyDesk for Linux to at least version 8.0.3, with the latest 8.1.0 release recommended where possible.[1][2] Administrators unable to patch immediately can reduce exposure by restricting or firewalling direct TCP access to port 7070, ensuring AnyDesk traffic is forced through the vendor’s relays, which are not affected by the exploit according to the initial impact assessment.[1][2][8] Security teams should also monitor for unusual inbound connections targeting AnyDesk services and consider the presence of outdated Linux clients as a potential indicator of elevated compromise risk, particularly in environments where remote desktop tools are widely deployed.[1][13]

References

  1. Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access
  2. The Hacker News | #1 Trusted Source for Cybersecurity News
  3. Anydesk CVEs and Security Vulnerabilities – OpenCVE
  4. Latest Anydesk Vulnerabilities
  5. AnyDesk pre-auth RCE vulnerability identified
  6. [CVE-2020-13160] AnyDesk
  7. AnyDesk

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply