Security researchers have publicly released a working proof of concept exploit for a previously patched vulnerability affecting AnyDesk Linux, demonstrating how attackers could achieve remote code execution with root privileges before a connection request is approved. The exploit, named AnyPwn, targets a heap buffer overflow within the remote desktop application’s session protocol and is designed for AnyDesk Linux version 8.0.2. Although AnyDesk addressed the issue with the release of version 8.0.3 in June, the company described the update only as a fix for a software bug that could cause a crash and did not assign a CVE identifier or publish a dedicated security advisory. Researchers released the proof of concept code through GitHub on October 8, prompting renewed attention to the importance of ensuring systems are updated to supported software versions. Administrators are advised to upgrade to at least version 8.0.3, while the latest available release is version 8.1.0.
According to the researchers, the published exploit currently functions only over direct TCP connections using port 7070. Successful exploitation depends on specific memory conditions, making the attack probabilistic rather than guaranteed. If the required heap layout is not present, the application is expected to crash instead of executing attacker supplied commands. The proof of concept is tailored specifically for AnyDesk Linux version 8.0.2, and researchers noted that different software builds would require modified offsets to achieve similar results. They also reported that the vulnerable code path can be reached through AnyDesk relay servers, which are used when direct peer to peer connections are unavailable. While this behavior was verified using instrumentation tools, the researchers did not demonstrate a complete exploit chain through relay infrastructure. AnyDesk previously stated that the vulnerability is limited to direct Linux connections that do not rely on relay servers and confirmed that Windows and macOS versions are not affected by the issue.
The researchers explained that the vulnerability originates from the way AnyDesk processes mode 5 stream packets within its session protocol. During packet handling, the application calculates the required memory allocation by adding a fixed header size to the declared payload length using 32 bit arithmetic without sufficient overflow validation. By supplying a specially crafted payload value, the calculation can wrap around, causing the software to allocate an unexpectedly small memory buffer while continuing to process the original oversized payload. This allows data to extend beyond the allocated memory region, potentially modifying adjacent memory structures. According to the published research, the exploit then uses a return oriented programming chain to execute arbitrary commands with root privileges. The flaw was identified by Rick de Jager of V12 Security using the company’s automated security code review platform. The V12 founders are also known for previously establishing security company Zellic and leading the competitive security research team Perfect Blue.
Researchers further observed that AnyDesk no longer provides version 8.0.2 through its official download page, although references to the release remain available in the product changelog. They also noted that earlier versions such as 8.0.1 may contain the same vulnerable code path, although successful exploitation of those releases has not been confirmed. At the time of publication, no CVE identifier had been assigned to the vulnerability, and AnyDesk had not issued a formal security advisory beyond the software update itself. Organizations that cannot immediately deploy updated software are advised to reduce exposure by restricting access to TCP port 7070 until upgrades can be completed. The latest disclosure follows earlier security activity involving the platform, including a separate heap buffer overflow addressed in 2025 and a production environment security incident disclosed in early 2024. The publication of the proof of concept reinforces the importance of applying vendor updates promptly and reviewing remote access infrastructure to minimize potential security risks.
Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.





