Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Exploit Exposes Root Access Flaw in AnyDesk Linux

Exploit Exposes Root Access Flaw in AnyDesk Linux

Posted on October 9, 2026 By CWS

Security researchers have unveiled a new exploit, AnyPwn, that targets a significant vulnerability in AnyDesk Linux. This flaw, located in the remote desktop tool’s session protocol, allows attackers to gain root access without authentication. The exploit was publicly released on GitHub on October 8, prompting administrators to ensure their systems are updated to at least version 8.0.3 to mitigate potential risks.

Details of the AnyDesk Exploit

The exploit leverages a heap buffer overflow within AnyDesk’s session management, specifically affecting direct TCP connections via port 7070. Successful execution requires precise conditions, such as the alignment of a target object next to the overflow buffer. The code, as released, is tailored for AnyDesk Linux version 8.0.2, with other versions requiring custom adjustments to the offsets.

Despite the lack of an assigned CVE or an official security advisory from AnyDesk, the urgency to update is clear. The company has acknowledged the vulnerability, affecting direct Linux connections while clarifying that Windows and macOS versions remain unaffected.

Understanding the Vulnerability Mechanism

AnyDesk’s session protocol uses mode-5 stream packets, where a miscalculation in the buffer allocation size creates the vulnerability. The flaw arises when a payload length of 0xFFFFFFF0 is declared, resulting in a zero-sized allocation due to arithmetic overflow. This allows malicious data to overflow into adjacent memory spaces, potentially executing commands with root privileges.

Rick de Jager from the V12 security team, using the V12 code review engine, identified the flaw. This discovery is part of a broader security landscape involving other vulnerabilities, like the previously patched CVE-2025-27918, which affected multiple platforms through a different mechanism.

Recommendations and Future Implications

Administrators are urged to upgrade to the latest version, 8.1.0, and restrict access to TCP port 7070 as an immediate precaution. While the exploit’s full potential over relay servers remains unconfirmed, ongoing vigilance and prompt software updates are essential in maintaining system security.

This incident underscores the critical importance of transparency and timely communication in cybersecurity. As vulnerabilities arise, the ability to quickly patch and inform users is paramount in safeguarding against potential exploits.

The Hacker News Tags:AnyDesk, cybersecurity advisory, exploit demonstration, heap buffer overflow, IT security, Linux security, network security, remote code execution, root access, security patch, software update, system vulnerability, tech news

Post navigation

Previous Post: Warden Stealer Malware Expands via ClickFix and Malvertising
Next Post: Anthropic’s OSS Scanner Enhances Open-Source Security

Related Posts

AI Agents and Identity Risks in Modern Enterprises AI Agents and Identity Risks in Modern Enterprises The Hacker News
Supply Chain Worm Exploits npm to Steal Developer Tokens Supply Chain Worm Exploits npm to Steal Developer Tokens The Hacker News
Hackers Target Over 70 Microsoft Exchange Servers to Steal Credentials via Keyloggers Hackers Target Over 70 Microsoft Exchange Servers to Steal Credentials via Keyloggers The Hacker News
Scattered Spider Hacker Arrests Halt Attacks, But Copycat Threats Sustain Security Pressure Scattered Spider Hacker Arrests Halt Attacks, But Copycat Threats Sustain Security Pressure The Hacker News
Rejetto HFS Vulnerability Exploited for Admin Access Rejetto HFS Vulnerability Exploited for Admin Access The Hacker News
FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic’s OSS Scanner Enhances Open-Source Security
  • Exploit Exposes Root Access Flaw in AnyDesk Linux
  • Warden Stealer Malware Expands via ClickFix and Malvertising
  • TP-Link Faces New Lawsuits Over Security and China Links
  • Hackers Exploit Terraform Workflows to Spread Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic’s OSS Scanner Enhances Open-Source Security
  • Exploit Exposes Root Access Flaw in AnyDesk Linux
  • Warden Stealer Malware Expands via ClickFix and Malvertising
  • TP-Link Faces New Lawsuits Over Security and China Links
  • Hackers Exploit Terraform Workflows to Spread Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark