A working proof-of-concept for a serious AnyDesk Linux vulnerability that can let remote attackers run commands as root without authentication or user approval.
The issue, named AnyPwn, affects AnyDesk Linux 8.0.2 and was fixed in version 8.0.3. Organizations using AnyDesk for Linux should update immediately and check whether TCP port 7070 is exposed to untrusted networks.
The flaw was discovered by Rick de Jager of the V12 security team using V12, an AI-powered security review platform. V12 first disclosed the issue publicly in June and described it as a pre-authentication, zero-click remote code execution flaw caused by a heap buffer overflow.
AnyDesk acknowledged the report the following day and released the 8.0.3 update in June. The public exploit code was later released on October 8, bringing fresh attention to systems that may still run the older Linux build.
AnyDesk Linux Flaw
According to technical documentation published by V12 Security, the issue exists in AnyDesk’s session protocol, which handles data exchanged while a remote client connects to the service.
In the affected version, the mode-5 stream packet handler accepts a remote payload length before safely validating it. The software then adds a 16-byte object header to that value using 32-bit arithmetic.
A specially formed length can cause that calculation to wrap around, leading the application to reserve a very small memory area while still treating it as a much larger object.
That mismatch creates an out-of-bounds write condition. Put simply, the attacker can send a small network packet that tells AnyDesk to expect a huge amount of data. The vulnerable service then writes attacker-controlled data beyond the small allocated memory area.
This can corrupt nearby objects in memory and, under the right conditions, redirect program execution. The researchers showed that the issue could be used to execute an arbitrary command through the AnyDesk service.
The security impact is severe because the AnyDesk service normally runs with root privileges on Linux. Root is the highest privilege level on the operating system, allowing control over files, processes, user accounts, and security settings.
An attacker who successfully triggers the flaw could gain a strong foothold on the affected host before a victim accepts a desktop-sharing request.
That makes this issue very different from many remote-support risks that require stolen credentials, user approval, or unattended-access passwords.
The released exploit targets AnyDesk Linux 8.0.2 running in service mode on x86_64 systems. It uses a direct connection to TCP port 7070 and depends on a specific memory layout, meaning exploitation is not guaranteed every time.
When the memory layout is unsuitable, the service may crash instead of running the attacker’s command. The published exploit also relies on offsets for the exact vulnerable build, so it should not be treated as proof that every AnyDesk Linux version can be exploited in the same way.
There is an important point about network exposure. AnyDesk initially said the issue was limited to direct Linux connections and did not affect Windows or macOS. The V12 researchers said they also reached the vulnerable code path through AnyDesk relay connections using a Frida-based test.
However, they did not demonstrate the full root-code-execution chain through relays. As a result, direct exposure of TCP/7070 is the confirmed risk, while full relay-based exploitation remains unresolved.
Administrators should first identify Linux machines running AnyDesk 8.0.2 or older builds and upgrade them to version 8.0.3 or later. Where patching cannot happen at once, teams should restrict inbound access to TCP/7070 at firewalls, VPN gateways, and cloud security groups.
They should also review AnyDesk service logs, unexpected root-level processes, and outbound connections from systems that exposed the port. AnyDesk’s Linux changelog records the vendor’s fixes, although the entry described this issue only as a bug that could lead to a crash rather than a security vulnerability.
The disclosure also adds to the security history of remote-access software, which is often installed on high-value servers and widely trusted by IT teams.
Cyber Security News previously reported on a separate AnyDesk flaw with a public proof-of-concept affecting Windows, while recent incident reporting has shown how legitimate remote-management tools such as AnyDesk can be used after compromise for continued access.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup into your SOC

