Skip to content

AnyDesk Linux pre-auth root RCE gets public exploit, no CVE

V12 published a working pre-auth exploit giving root on AnyDesk Linux 8.0.2 over TCP/7070. AnyDesk fixed it silently in 8.0.3 in June with no CVE and a 'crash' changelog note.

Published 3 min read

Researchers at V12 have published a working exploit, dubbed AnyPwn, for a pre-authentication remote code execution flaw in AnyDesk for Linux 8.0.2. Per the repository, "successful exploitation yields root command execution before desktop-control approval," because the AnyDesk service "normally runs as root on Linux." The proof of concept went up on GitHub on October 8.

What the bug does

The exploit reaches a vulnerable session-protocol path over AnyDesk's direct TCP/7070 transport and executes code before the operator ever sees — let alone approves — an incoming connection request. V12 credits the find to Rick de Jager, using the team's code-review engine.

Two caveats worth stating plainly. The exploit is probabilistic: a failed attempt crashes the AnyDesk service rather than popping a shell. And V12 says the same vulnerable path is reachable over AnyDesk's relay servers — validated with a Frida trigger — but they did not demonstrate a full relay exploit chain. So the public PoC lands over direct connections; relay-side exploitation is plausible but unproven.

Patch status

AnyDesk fixed the flaw in 8.0.3, released in June. Its changelog described the fix only as "fixed a bug that could lead to a crash." No CVE was assigned, and AnyDesk published no security advisory. As The Hacker News notes, AnyDesk told it the issue is "limited to direct connections on Linux (connections that do not go through our relays). Windows and macOS are not affected." The current release is 8.1.0.

No in-the-wild exploitation has been reported.

Action checklist

  1. Upgrade every Linux AnyDesk install to 8.1.0. Anything on 8.0.2 or earlier should be treated as vulnerable; V12 suspects 8.0.1 and earlier share the code path, unconfirmed.
  2. If you cannot upgrade immediately, block inbound TCP/7070 to Linux hosts running AnyDesk and rely on relay connections only.
  3. Inventory where AnyDesk runs as root on Linux endpoints — that is the privilege an attacker inherits on a hit.

What other outlets missed

The news peg here is not a CVE — there isn't one. AnyDesk shipped a silent fix in June under a "crash" label, with no advisory and no identifier, and the severity only became public when V12 released the PoC four months later. For anyone tracking exposure by CVE feed or KEV catalog, a pre-auth root RCE in a widely deployed remote-access tool simply did not exist. That gap — a real root-level flaw with no number attached to it — is the story. If your patch process keys off CVE IDs, a changelog line about "a crash" is the kind of entry it will skip.

Related stories