Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access
Researchers released AnyPwn, a working pre-auth root exploit for AnyDesk Linux before 8.0.3.
Researchers published AnyPwn on GitHub on October 8, a working exploit for a pre-authentication heap buffer overflow in AnyDesk Linux's session protocol that can run a command as root. AnyDesk patched the flaw in version 8.0.3 in June but described it only as a crash fix, with no CVE or security advisory. The public exploit targets build 8.0.2 over direct TCP port 7070 and is probabilistic; full exploitation through AnyDesk relays was not demonstrated. A separate heap overflow, CVE-2025-27918, was fixed earlier in version 7.0.0.