Security researchers have published a working exploit, named AnyPwn, for a pre-authentication remote code execution vulnerability in AnyDesk for Linux. The flaw, a heap buffer overflow in the remote desktop tool's session protocol, can let an unauthenticated attacker execute arbitrary commands as root before a user approves an incoming connection. AnyDesk fixed the issue in version 8.0.3 in June, but the changelog only described the change as fixing a crash; no CVE was assigned and no security advisory was issued.

The exploit works over direct TCP connections on port 7070 and is probabilistic: the heap layout must place a target object next to the overflowed buffer, or the service crashes. The published offsets target AnyDesk Linux 8.0.2 specifically. The bug arises because the handler for mode-5 stream packets adds a 16-byte header to the declared payload length using 32-bit arithmetic without overflow checking. A payload length of 0xFFFFFFF0 wraps the result to zero, causing the allocator to reserve a tiny buffer while the object records the original large length, allowing attacker data to overwrite adjacent heap objects and pivot to a ROP chain.

The researchers state that the same vulnerable code path is reachable via AnyDesk's relay servers, which the software uses when direct connections are unavailable, and they validated this with a Frida instrumentation trigger. AnyDesk, however, said in June that the vulnerability is limited to direct connections on Linux and does not affect Windows or macOS. The full exploit chain over relays has not been demonstrated. Administrators should update to AnyDesk Linux 8.0.3 or later, and can reduce exposure by restricting access to TCP port 7070.