Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

    October 10, 2026

    Solana doubles block production speed to 200ms as network prepares for Alpenglow upgrade

    October 10, 2026

    A 9-billion-year-old signal could help explain dark energy

    October 10, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks
    • Solana doubles block production speed to 200ms as network prepares for Alpenglow upgrade
    • A 9-billion-year-old signal could help explain dark energy
    • Russian Sabotage in Europe Is No Longer ‘Symbolic,’ Estonian Counterintelligence Chief Says
    • Hegseth says Pentagon plans to livestream Fort Hood shooter’s execution. Is that legal?
    • US judge rules Trump administration’s use of voter data unlawful | US Midterm Elections 2026 News
    • Long live the mechanical keyboard
    • Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, October 10
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKOctober 9, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalOct 09, 2026Vulnerability / Endpoint Security

    Security researchers have published a full working exploit for a pre-authentication remote code execution flaw in AnyDesk Linux that gives attackers root access before anyone approves the connection.

    AnyDesk patched the flaw in version 8.0.3 in June, but its changelog described the fix only as “fixed a bug that could lead to a crash,” with no CVE assigned and no security advisory.

    The exploit, called AnyPwn, targets a heap buffer overflow in AnyDesk’s session protocol, a remote desktop tool. The code was released on GitHub on October 8.

    Administrators should update AnyDesk Linux to at least version 8.0.3. The latest release is 8.1.0.

    What the Exploit Demonstrates

    The published exploit works only over direct TCP connections on port 7070.

    The exploit is probabilistic: the heap layout must place a target object adjacent to the overflowed buffer; otherwise, the service crashes instead of executing the attacker’s command. The offsets in the published code target a specific build of AnyDesk Linux, 8.0.2; other builds would require different values.

    Cybersecurity

    The researchers say the same vulnerable code path is also reachable via AnyDesk’s relay servers, which the software uses when a direct connection is unavailable. They validated this with a Frida instrumentation trigger but did not demonstrate the full exploit chain over relays.

    AnyDesk said in June that the vulnerability is “limited to direct connections on Linux (connections that do not go through our relays). Windows and macOS are not affected.”

    The exploit targets AnyDesk Linux 8.0.2. The researchers imply that earlier versions, such as 8.0.1, may share the vulnerable code path, but exploitation of those versions has not been confirmed.

    The researchers announced the flaw on June 22. AnyDesk acknowledged it the next day and released version 8.0.3 with the fix.

    No CVE has been assigned to the vulnerability as of October 9. AnyDesk has not issued a formal security advisory.

    AnyDesk’s download page no longer lists version 8.0.2, though it still appears in the changelog. “The vendor appears to have deleted (?) the 8.0.2 build of AnyDesk upon the release of our poc video,” the researchers wrote.

    Administrators who cannot update immediately can reduce exposure by restricting access to TCP port 7070. Whether the flaw is fully exploitable over relay connections remains unresolved.

    How the Flaw Works

    AnyDesk’s session protocol uses mode-5 stream packets. The handler calculates the size of its backing allocation by adding a 16-byte header to the declared payload length, using 32-bit arithmetic without overflow checking.

    The exploit declares a payload length of 0xFFFFFFF0. Adding 0x10 wraps the 32-bit result to zero, so the allocator reserves a tiny buffer while the object records the original large length. Even one byte of attacker data then writes past the end of the allocation.

    The overflow corrupts fields in adjacent heap objects, and the exploit uses a ROP chain to run an arbitrary command as root.

    Cybersecurity

    The vulnerability was found by Rick de Jager of the V12 security team using V12, a security code review engine. V12’s founders previously built security firm Zellic and led the competitive hacking team Perfect Blue.

    A separate AnyDesk heap buffer overflow, CVE-2025-27918, was fixed in version 7.0.0 in April 2025. That vulnerability affected all AnyDesk platforms and involved an integer overflow in user image processing, a different mechanism from AnyPwn’s session protocol flaw.

    AnyDesk was hacked in early 2024 in a separate incident in which the company’s production systems were breached, leading to certificate revocations and forced password resets.

    access AnyDesk exploit Flaw Linux PreAuth publish researchers Root working
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

    FBI Arrests Another ShinyHunters Suspect Reportedly Involved in Its Jobs Portal Hack

    Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

    Unpatched AhsayCBS Vulnerabilities Exploited in the Wild

    Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto

    TP-Link Sued by Four More U.S. States Over Router Security and China Ties

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

    October 10, 2026

    Solana doubles block production speed to 200ms as network prepares for Alpenglow upgrade

    October 10, 2026

    A 9-billion-year-old signal could help explain dark energy

    October 10, 2026

    Russian Sabotage in Europe Is No Longer ‘Symbolic,’ Estonian Counterintelligence Chief Says

    October 10, 2026
    Latest Posts

    Reform donor Arron Banks urged to set out extent of surveillance of journalists | Arron Banks

    August 10, 2026

    The Canadian Secessionists Who Love Trump

    August 10, 2026

    How ‘Harry Potter’ Fans Protected Dobby’s Grave From the Path of a U.K.-Ireland Power Line

    August 10, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Hackers abuse Google Ads, Bing redirects to push Claude ClickFix attacks

    October 10, 2026

    Solana doubles block production speed to 200ms as network prepares for Alpenglow upgrade

    October 10, 2026

    A 9-billion-year-old signal could help explain dark energy

    October 10, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.