Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access
Researchers published the AnyPwn exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that can lead to root access before a connection is approved. AnyDesk fixed the issue in version 8.0.3, but the bug was initially disclosed without a CVE or formal security advisory, and the exploit targets AnyDesk Linux 8.0.2 over direct TCP connections on port 7070. #AnyPwn #AnyDesk #V12

Keypoints

  • AnyPwn exploits a heap buffer overflow in AnyDesk’s session protocol.
  • The flaw allows pre-authentication remote code execution with root privileges.
  • AnyDesk patched the issue in version 8.0.3, with 8.1.0 now available.
  • The published exploit works against direct TCP connections on port 7070.
  • Researchers say relay-based exploitation may also be possible, but it is not confirmed.

Read More: https://thehackernews.com/2026/10/researchers-publish-working-exploit-for.html