Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

The Hacker News by The Hacker News
October 9, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Swati KhandelwalOct 09, 2026Vulnerability / Endpoint Security

Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection.

AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as “fixed a bug that could lead to a crash,” with no CVE assigned and no security advisory.

The exploit, called AnyPwn, targets a heap buffer overflow in AnyDesk’s session protocol, a remote desktop tool. The code was released on GitHub on October 8.

Administrators should update AnyDesk Linux to at least version 8.0.3. The latest release is 8.1.0.

What the Exploit Demonstrates

The published exploit works only over direct TCP connections on port 7070.

The exploit is probabilistic: the heap layout must place a target object adjacent to the overflowed buffer; otherwise, the service crashes instead of executing the attacker’s command. The offsets in the published code target a specific build of AnyDesk Linux, 8.0.2; other builds would require different values.

The researchers say the same vulnerable code path is also reachable via AnyDesk’s relay servers, which the software uses when a direct connection is unavailable. They validated this with a Frida instrumentation trigger but did not demonstrate the full exploit chain over relays.

AnyDesk said in June that the vulnerability is “limited to direct connections on Linux (connections that do not go through our relays). Windows and macOS are not affected.”

The exploit targets AnyDesk Linux 8.0.2. The researchers imply that earlier versions, such as 8.0.1, may share the vulnerable code path, but exploitation of those versions has not been confirmed.

The researchers announced the flaw on June 22. AnyDesk acknowledged it the next day and released version 8.0.3 with the fix.

No CVE has been assigned to the vulnerability as of October 9. AnyDesk has not issued a formal security advisory.

AnyDesk’s download page no longer lists version 8.0.2, though it still appears in the changelog. “The vendor appears to have deleted (?) the 8.0.2 build of AnyDesk upon the release of our poc video,” the researchers wrote.

Administrators who cannot update immediately can reduce exposure by restricting access to TCP port 7070. Whether the flaw is fully exploitable over relay connections remains unresolved.

How the Flaw Works

AnyDesk’s session protocol uses mode-5 stream packets. The handler calculates the size of its backing allocation by adding a 16-byte header to the declared payload length, using 32-bit arithmetic without overflow checking.

The exploit declares a payload length of 0xFFFFFFF0. Adding 0x10 wraps the 32-bit result to zero, so the allocator reserves a tiny buffer while the object records the original large length. Even one byte of attacker data then writes past the end of the allocation.

The overflow corrupts fields in adjacent heap objects, and the exploit uses a ROP chain to run an arbitrary command as root.

The vulnerability was found by Rick de Jager of the V12 security team using V12, a security code review engine. V12’s founders previously built security firm Zellic and led the competitive hacking team Perfect Blue.

A separate AnyDesk heap buffer overflow, CVE-2025-27918, was fixed in version 7.0.0 in April 2025. That vulnerability affected all AnyDesk platforms and involved an integer overflow in user image processing, a different mechanism from AnyPwn’s session protocol flaw.

AnyDesk was hacked in early 2024 in a separate incident in which the company’s production systems were breached, leading to certificate revocations and forced password resets.



Source link

The Hacker News

The Hacker News

Next Post

TP-Link Sued by Four More U.S. States Over Router Security and China Ties

Recommended.

Appeals Court Lets the Pentagon Designate Anthropic a Supply-Chain Risk

September 25, 2026
Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023

Ransomware Negotiator Pleads Guilty to Aiding BlackCat Attacks in 2023

April 21, 2026

Trending.

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

AWS, Google, Oracle, Microsoft Top Gartner’s Cloud AI Infrastructure List For 2026

July 29, 2026
IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

IDCA datacentres report: Global concentration and the Goldilocks zone | Computer Weekly

May 12, 2026
How ByteDance Made China’s Most Popular AI Chatbot

How ByteDance Made China’s Most Popular AI Chatbot

October 16, 2025
The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

The Coolest Big Data System and Platform Companies Of The 2026 Big Data 100

June 9, 2026

AWS Pours $6B Into New US Data Center As Amazon’s $220B Spending Goal Unfolds

August 20, 2026

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio