Public exploit gives root on Linux machines running AnyDesk 8.0.2

10.10.2026 4 min 50

Researchers have published a working exploit for AnyDesk on Linux that runs commands as root on a target machine without a password and before anyone accepts the connection. The exploit, called AnyPwn, targets AnyDesk 8.0.2 running as a service and reaches it over TCP port 7070. AnyDesk fixed the flaw in version 8.0.3 in June, but the changelog called it only "fixed a bug that could lead to a crash", with no CVE and no security advisory, so many administrators had no reason to treat the update as urgent.

What the exploit does

The bug was found by Rick de Jager of the security firm V12, which published the proof of concept on GitHub on October 8. It is a heap overflow in the code that handles the first packets of a session: AnyDesk trusts a length field sent by the remote side before checking it, the number wraps around, and the program copies attacker data past a tiny buffer. On Linux the AnyDesk service normally runs as root, so code executed this way gets full control of the machine. No click or approval from the person at the screen is needed.

The public exploit has limits. It was built for one build of 8.0.2 on 64-bit Linux, it needs a direct connection to port 7070, and it does not work every time: when the memory layout is wrong, the AnyDesk service crashes instead. The researchers say 8.0.1 may contain the same flaw but did not port the exploit to it. AnyDesk says the issue is "limited to direct connections on Linux (connections that do not go through our relays)" and does not affect Windows or macOS. V12, however, says it confirmed that the vulnerable code can also be reached through AnyDesk's relay servers. It did not build a full exploit for that path, so whether relayed connections are exploitable remains open.

Why the patch was missed

Security teams usually decide what to patch first by CVE numbers and vendor advisories. As of October 9 this flaw had neither, so scanners and patch dashboards that rely on CVE feeds had nothing to flag. A Linux machine that last updated AnyDesk before June still runs a version for which a public exploit now exists. According to V12, the vendor removed the 8.0.2 build from its site after the researchers released a video of the attack.

Check your machines

  1. Find the version: run anydesk --version. Anything below 8.0.3 needs updating. The current release is 8.1.0.
  2. See whether the service is listening: sudo ss -ltnp | grep 7070. A line with anydesk means the port is open on that machine.
  3. Update through your package manager or AnyDesk's repository, then restart the service with sudo systemctl restart anydesk.
  4. Close port 7070 to the internet at the host firewall, the router and any cloud security group. Updating is the fix. Closing the port is a second barrier while the question of relayed connections stays open.
  5. Look for warning signs: repeated crashes of the AnyDesk service, unexpected connections to port 7070 and processes started by the AnyDesk service that nobody launched.

A remote desktop service that listens on the open internet is a risk even when it is fully patched. Keeping it reachable only through a VPN or another private network into the office or home network means a flaw like this one cannot be hit from the internet at all, only by someone who already has access to that network. The same applied to the SSH flaw in MikroTik routers. Our WireGuard setup guide shows how to run such a tunnel on your own server.

anydesklinuxvulnerabilitycybersecurityvpn

Read also