A significant vulnerability in AnyDesk Linux has been identified, enabling remote attackers to execute commands with root privileges without requiring authentication. This issue, labeled ‘AnyPwn,’ affects AnyDesk version 8.0.2 and was resolved in version 8.0.3. Organizations using AnyDesk on Linux should prioritize updating their systems and ensure that TCP port 7070 is not exposed to unsecured networks.
Discovery and Immediate Response
The flaw was discovered by Rick de Jager from the V12 security team using their AI-driven platform, V12. The vulnerability was first made public in June, characterized as a pre-authentication, zero-click remote code execution weakness resulting from a heap buffer overflow. AnyDesk acknowledged the vulnerability promptly and released an update to address the issue. The public release of exploit code on October 8 has renewed focus on systems that have not yet been updated.
Technical Insights into the Vulnerability
According to technical documentation by V12 Security, the flaw resides in AnyDesk’s session protocol, which manages data during a remote connection. In the vulnerable version, the mode-5 stream packet handler fails to validate remote payload length properly. This oversight allows a calculation wrap-around, causing the application to allocate insufficient memory while treating it as a larger object, leading to an out-of-bounds write condition.
This vulnerability permits attackers to overflow memory and inject commands into the AnyDesk service, which operates with root privileges on Linux systems. This level of access could allow attackers to establish a stronghold on a system before any desktop-sharing request is accepted, bypassing common security safeguards like stolen credentials or user approval.
Exploitation and Mitigation Strategies
The exploit targets AnyDesk Linux 8.0.2 in service mode on x86_64 architectures, relying on specific memory layouts. Exploitation is not guaranteed, as an unsuitable memory layout may cause the service to crash instead. Additionally, the exploit’s reliance on exact build offsets means it cannot be generalized to all AnyDesk Linux versions.
For network exposure, direct threats are confirmed on TCP port 7070, though the vulnerability’s impact through relay connections remains partially unresolved. Administrators should update AnyDesk installations to 8.0.3 or later and limit inbound access to TCP/7070 until patching is complete. Reviewing service logs and monitoring for unusual root-level activities is also recommended.
The incident highlights the ongoing security challenges associated with remote-access software, which is frequently deployed on high-value infrastructure and trusted by IT departments. Previous reports have shown similar vulnerabilities in AnyDesk for Windows, underscoring the importance of comprehensive security practices.
Conclusion
This disclosure serves as a reminder of the critical role of timely software updates and vigilant security measures in protecting IT infrastructure. Organizations are urged to assess their exposure to this vulnerability and take immediate corrective actions to safeguard their systems.
