Security experts have released a functional exploit demonstrating how a vulnerability in AnyDesk for Linux could be abused to gain the highest level of system privileges without authentication. The flaw could put computers running vulnerable versions of the remote desktop software at risk if attackers can reach the affected service.
The exploit, called AnyPwn, shows a weakness in the way AnyDesk processes certain connection data. Researchers demonstrated that the vulnerability could be exploited to execute code with root-level permissions on a targeted Linux machine.
AnyDesk is widely used for remote access, technical support and system administration. A security weakness in such software can be particularly dangerous because it may provide attackers with a route into systems that would otherwise be protected by authentication mechanisms.
How the flaw works
The security issue stems from a heap buffer overflow associated with AnyDesk's session protocol. Researchers linked the problem to an integer overflow that can cause the application to allocate an insufficient amount of memory when processing incoming data.
A buffer overflow occurs when a program writes more data into a memory area than it was designed to hold. This can damage adjacent memory and, under certain circumstances, allow an attacker to influence the program's execution.
In the reported case, the integer overflow affects the memory allocation process, creating conditions that can be exploited to compromise the application. The researchers developed AnyPwn to demonstrate that the weakness could be triggered before authentication.
The exploit was tested against AnyDesk for Linux version 8.0.2. Researchers demonstrated exploitation through direct TCP connections on port 7070. However, they did not establish that the same attack could be completed through AnyDesk's relay infrastructure.
Risks for Linux systems
The possibility of obtaining root privileges makes the vulnerability especially dangerous. Root access gives a user or process extensive control over a Linux system, including the ability to modify protected files, change configurations and install software.
An attacker who successfully exploits the flaw could potentially gain control of an affected computer, access confidential information or deploy malicious tools. In an organizational environment, a compromised machine could also become a foothold for further attacks against internal systems.
Updates and security recommendations
According to the report, AnyDesk fixed the vulnerability in version 8.0.3, released in June 2026. Users running earlier Linux versions should update to version 8.0.3 or a newer supported release.
Read the original article:
