Skip to content
THREATWIRE

Research

AnyDesk Linux AnyPwn exploit targets a fixed pre-auth bug

V12 published AnyPwn, a working exploit for a heap buffer overflow in AnyDesk for Linux 8.0.2 that the researchers say gives root before a connection is approved. AnyDesk fixed it in 8.0.3 in June with a one-line changelog entry. No CVE, no vendor advisory, not in CISA KEV, no known exploitation.

Critical

Published 9 Oct 2026

PoC link

On this page

What happened

On 22 June 2026 the V12 security team announced AnyPwn. It is a heap buffer overflow in the session protocol of AnyDesk for Linux. Researcher Rick de Jager found it with V12's code review engine. AnyDesk acknowledged the report the next day. It shipped Linux version 8.0.3 on 23 June 2026.

The 8.0.3 changelog entry reads only "Fixed a bug that could lead to a crash." AnyDesk published no security advisory. No CVE has been assigned as of 9 October 2026.

On 8 October 2026 V12 added a working exploit to its public proof-of-concept repository on GitHub. The researchers say it runs a command as root on the target. It does so before anyone accepts the incoming connection.

At a high level, a size calculation in the session handler can overflow. The service then reserves a heap buffer that is too small. Incoming data written past that buffer corrupts nearby memory, which the exploit turns into code execution.

Who is affected

The published exploit targets AnyDesk for Linux 8.0.2, released on 1 April 2026. Version 8.0.3 and later contain the fix. The current Linux release is 8.1.0, dated 23 September 2026.

AnyDesk said in June that the issue is limited to direct connections on Linux. Those are connections that do not go through AnyDesk's relays. AnyDesk said Windows and macOS are not affected.

The researchers suggest earlier Linux builds such as 8.0.1 may share the vulnerable code. Exploitation of those builds has not been shown.

What is confirmed

AnyDesk confirmed the vulnerability in June and scoped it to direct Linux connections. Its changelog dates the fix to 8.0.3 on 23 June 2026.

The exploit was published by the V12 security team in its public PoC repository on 8 October 2026. V12 claims pre-authentication remote code execution as root against AnyDesk for Linux 8.0.2. The claimed path is a direct TCP connection to port 7070, before the connection is approved. ThreatWire did not run the exploit. Availability is therefore PoC.

According to reporting on the release, the exploit is probabilistic. When memory is not laid out as expected, the service crashes instead. The published code is tuned to the 8.0.2 build only.

The issue is not in the CISA KEV catalog. AnyDesk said in June it had no evidence of exploitation against its infrastructure or customers.

What is not confirmed

Full exploitation over AnyDesk relay connections is not confirmed. The researchers say the vulnerable code is reachable through relays. They showed this with an instrumentation trigger, not a full chain. AnyDesk's own statement limits the issue to direct connections.

There is no CVE ID and no CVSS score. Some secondary sites link AnyPwn to CVE-2025-27918. That is a different AnyDesk heap overflow, in user image handling, fixed for Linux in 7.0.0 in April 2025. ThreatWire found no reports of exploitation in the wild from AnyDesk or CISA.

What to do

Update AnyDesk for Linux to 8.0.3 or later. The current release, 8.1.0, is the better target. Check fleets and golden images for any 8.0.x build below 8.0.3.

If you cannot update at once, block inbound TCP port 7070 to Linux hosts running AnyDesk. Allow it only from trusted networks.

Remove AnyDesk from Linux servers that do not need remote desktop access. Watch for unexpected AnyDesk service crashes on Linux hosts that are still unpatched.

Sources: AnyDesk changelog for Linux, The Hacker News report on AnyPwn, NVD for CVE-2025-27918, CISA KEV (not listed), and the public V12 repository metadata.

Sources

Share on X@threatwire_https://www.threatwire.tech/research/anydesk-linux-anypwn-exploit-targets-fixed-pre-auth-bug

More articles