Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Threat Intelligence: Exploiting the AnyDesk Linux Flaw for Root Access




A new exploit has been discovered in AnyDesk Linux, which allows attackers to gain root access before anyone approves the connection. This vulnerability, known as AnyPwn, targets a heap buffer overflow in AnyDesk's session protocol and has been identified as a significant threat to Linux users. With this vulnerability, attackers can execute arbitrary commands as root, giving them full control over the system. It is essential to update AnyDesk Linux to at least version 8.0.3 to avoid this vulnerability and to take other necessary security measures to protect against remote code execution vulnerabilities.

  • The AnyDesk Linux flaw, also known as AnyPwn, is a pre-authentication remote code execution vulnerability that allows attackers to gain root access.
  • The vulnerability targets AnyDesk Linux version 8.0.2 and has been identified as a significant threat to Linux users.
  • The exploit targets a heap buffer overflow in AnyDesk's session protocol and can only be executed over direct TCP connections on port 7070.
  • The vulnerability can be mitigated by updating to version 8.0.3 or restricting access to TCP port 7070.
  • Windows and macOS are not affected by this vulnerability.



  • The AnyDesk Linux flaw, also known as AnyPwn, is a pre-authentication remote code execution vulnerability that gives attackers root access before anyone approves the connection. This vulnerability was discovered by security researcher Rick de Jager of the V12 security team and has been identified as a significant threat to Linux users.

    The AnyDesk Linux version 8.0.2 is the target of this vulnerability, although other versions may also be affected. The exploit targets a heap buffer overflow in AnyDesk's session protocol, which is a remote desktop tool. The exploit was published on GitHub on October 8, 2026, and has been confirmed to work only over direct TCP connections on port 7070.

    The AnyPwn exploit is probabilistic, meaning that the heap layout must place a target object adjacent to the overflowed buffer for the exploit to succeed. However, the service crashes instead of executing the attacker's command if the heap layout does not meet the required conditions. The offsets in the published code target a specific build of AnyDesk Linux, 8.0.2; other builds would require different values.

    The researchers have also validated that the same vulnerable code path is also reachable via AnyDesk's relay servers, which the software uses when a direct connection is unavailable. However, the full exploit chain over relays has not been demonstrated.

    AnyDesk has stated that the vulnerability is limited to direct connections on Linux (connections that do not go through their relays). Windows and macOS are not affected by this vulnerability. The company released version 8.0.3 with a fix for this vulnerability in June 2026, but it did not provide any additional information about the vulnerability.

    The AnyPwn exploit is a significant threat to Linux users, as it allows attackers to gain root access without any authentication or verification. This means that if an attacker can exploit this vulnerability, they can gain full control over the system and execute arbitrary commands as root.

    Administrators are advised to update AnyDesk Linux to at least version 8.0.3 to avoid this vulnerability. However, for those who cannot update immediately, they can reduce exposure by restricting access to TCP port 7070.

    The AnyPwn exploit is a reminder of the importance of staying up-to-date with the latest security patches and updates. It also highlights the need for robust security measures to protect against remote code execution vulnerabilities.

    The discovery of this vulnerability is a significant threat to the security of Linux users, and it emphasizes the importance of vigilance and proactive measures to protect against such threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Threat-Intelligence-Exploiting-the-AnyDesk-Linux-Flaw-for-Root-Access-ehn.shtml

  • https://thehackernews.com/2026/10/researchers-publish-working-exploit-for.html


  • Published: Fri Oct 9 11:06:14 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us