Vulnerabilities

Public AnyPwn exploit gives root on unpatched AnyDesk for Linux

Exploit code for a pre-auth root flaw in AnyDesk for Linux 8.0.2 is public. The June fix had no CVE, so scanners may miss exposed hosts.

Illustration of a Linux server with a warning symbol representing the AnyDesk AnyPwn remote code execution flaw

A working proof-of-concept exploit for a pre-authentication flaw in AnyDesk for Linux is now public, and it can hand an attacker root on an unpatched host. AnyDesk shipped the fix in June as a routine crash repair, with no CVE and no advisory, so many organisations may not know they are exposed.

What happened

On 8 October 2026, researchers from the V12 security team released exploit code on GitHub for a remote code execution bug in the Linux build of AnyDesk, the remote access tool used heavily by IT support desks and managed service providers. They call it AnyPwn. The bug was found by Rick de Jager of V12, reportedly with help from the team’s automated code review engine.

The flaw affects AnyDesk for Linux 8.0.2. An attacker who can reach the AnyDesk service needs no credentials, and nobody has to approve an incoming session, before the vulnerable code runs. Because the Linux service normally runs as root, successful exploitation means full control of the machine.

The timeline is the uncomfortable part. V12 says it reported the issue on 22 June and AnyDesk acknowledged it the following day. Version 8.0.3 followed in June with the fix, but the changelog entry described it only as a bug “that could lead to a crash”. As of 9 October no CVE identifier had been assigned and no security advisory had been published, according to The Hacker News. The current release is 8.1.0. AnyDesk says the Windows and macOS clients are not affected.

The technical picture

At heart this is a memory corruption bug. When the AnyDesk service processes certain packets in its session protocol, it trusts a length value supplied by the remote party before checking it. A 32-bit size calculation can then wrap around, so the service allocates a tiny heap buffer while believing it is far larger. Writing past the end of that buffer corrupts memory, which a skilled attacker can turn into control of execution.

A few caveats matter for risk assessment:

  • The public exploit is tuned for one build: AnyDesk 8.0.2, running in service mode on x86_64. Whether 8.0.1 shares the vulnerable path has not been confirmed.
  • It is probabilistic. It depends on how the heap is laid out, and a failed attempt tends to crash the service rather than run code.
  • The demonstrated attack uses a direct TCP connection to port 7070.

The open question is AnyDesk’s relay network. The vendor has said the problem is confined to direct connections on Linux. V12 says it reached the vulnerable code through a relay connection in testing, but did not take that path all the way to code execution. Until someone settles that question, I would not treat relay-only operation as a complete defence.

This is not AnyDesk’s first heap overflow. CVE-2025-27918, fixed in version 7.0.0, affected every platform. The company also disclosed a breach of its production systems in early 2024.

Timeline of the AnyPwn AnyDesk for Linux flaw from June disclosure to public exploit release on 8 October 2026

Why it matters for UK organisations

Remote access software sits in a privileged position on any network. It is installed to let outsiders in, it often runs with the highest privileges on the host, and it is frequently deployed by third parties rather than by the organisation’s own IT team. Across the UK, AnyDesk is common in MSP toolkits, in vendor support arrangements for line-of-business systems, and on Linux boxes that run kiosks, signage, lab equipment and industrial front-ends.

The silent fix creates a specific problem. Most vulnerability management programmes are driven by CVE identifiers. If a flaw has no CVE, commercial scanners are unlikely to raise it, patch dashboards will not show it as a security update, and change boards may wave version 8.0.3 through as a cosmetic upgrade or skip it entirely. A Linux host running 8.0.2 could easily look clean in a monthly report.

The NCSC has repeatedly highlighted remote access tooling and supply chain access through service providers as weak points for UK organisations. A pre-authentication root bug in a remote support agent, with public code available, fits that pattern. Organisations preparing for the Cyber Security and Resilience Bill, which brings managed service providers into scope, should note that this is precisely the type of exposure regulators will expect MSPs to find and fix quickly.

Expert view

When we test networks, remote access agents are one of the first things we enumerate, because they are so often forgotten. Someone installs one for a supplier, the job finishes, and the agent stays behind for years with a listening port nobody owns. Linux estates are worse for this than Windows, because endpoint management on Linux tends to be patchier and asset registers are thinner.

The disclosure handling here deserves criticism. A pre-authentication, root-level memory corruption flaw in a widely deployed remote access product is a security issue, and describing its fix as a crash repair leaves defenders blind. Vendors do not need to publish exploit detail, but they do owe customers a clear statement that an update is security-relevant and a CVE that tooling can track. In my experience, quiet fixes surface at the worst moment, when public exploit code appears.

Nor should the exploit’s unreliability reassure anyone. Public code tends to be refined by others once it is out, and even a failed attempt knocks over a support channel.

What to do now

  1. Find every Linux AnyDesk install. Search software inventories, package managers and process lists for AnyDesk on Linux, including servers, appliances and machines managed by suppliers. Do not rely on CVE-based scanner output, because there is no CVE to match.
  2. Upgrade to 8.0.3 or later, ideally 8.1.0. Treat it as a security update with an urgent change window. This maps to the Cyber Essentials security update management control, which expects high-risk fixes within 14 days; given public exploit code, aim for much sooner.
  3. Close port 7070 at the perimeter. Block inbound TCP 7070 from the internet at firewalls, cloud security groups and VPN gateways, and limit it internally to the systems that genuinely need it. This is the Cyber Essentials firewall control in practice.
  4. Remove what you do not need. Uninstall AnyDesk where there is no current business reason for it, and agree with suppliers which remote access tool they may use and when (secure configuration and user access control).
  5. Look for signs of abuse on any host that ran 8.0.2. Review logs for repeated connections to port 7070, unexplained AnyDesk service crashes or restarts, unexpected processes started by the AnyDesk service, and unusual outbound traffic.
  6. Segment remote access hosts. Machines running remote support agents should not have unrestricted reach into sensitive internal systems.
  7. Ask your MSP directly. If a provider uses AnyDesk to support your estate, ask for written confirmation of the versions in use on Linux and when they were updated.

Bottom line

AnyPwn is a serious flaw made more dangerous by the way it was fixed. Public exploit code now exists for a pre-authentication root bug in AnyDesk for Linux 8.0.2, and the absence of a CVE means standard tooling may not flag it. Inventory your Linux remote access agents by hand, move them to 8.0.3 or later, and keep port 7070 off the internet. Vendors, meanwhile, should label security fixes for what they are.

Sources