Researchers Release Working Exploit for Critical Windows Vulnerability With 9.8 Severity Score
Security researchers have publicly released a working exploit for a critical remote code execution vulnerability in AnyDesk's Linux client that allows attackers to gain root access without user interaction. The flaw, dubbed AnyPwn, stems from a heap buffer overflow in the application's session protocol and was quietly patched in version 8.0.3 back in June 2024. However, AnyDesk never assigned a CVE identifier or issued a proper security advisory, instead burying the fix in their changelog as a generic crash bug. The exploit code appeared on GitHub in early October, potentially exposing organizations still running older versions.
The vulnerability exploits an integer overflow in how AnyDesk processes stream packet sizes. When the software calculates buffer allocation size, it adds a 16-byte header to the payload length using 32-bit arithmetic without checking for overflow. By specifying a payload length of 0xFFFFFFF0, attackers can cause the calculation to wrap around to zero, resulting in a tiny buffer being allocated while the system believes it has reserved much more space. This allows attackers to overflow the buffer and corrupt adjacent heap objects, ultimately executing a ROP chain to run arbitrary commands with root privileges.
The exploit primarily works through direct TCP connections on port 7070, though researchers suggest the vulnerable code path might also be reachable through AnyDesk's relay servers, which handle connections when direct communication isn't possible. Success isn't guaranteed on every attempt because exploitation depends on favorable heap memory layout, and the published exploit specifically targets version 8.0.2 with hardcoded offsets. AnyDesk initially stated the issue was limited to Linux systems with direct connections, but the full scope remains somewhat unclear.
Administrators should immediately update AnyDesk Linux installations to version 8.0.3 or later, with 8.1.0 being the current release. Organizations unable to patch immediately can mitigate risk by blocking or restricting access to TCP port 7070. The vulnerability was discovered by Rick de Jager using V12, a security code review engine, and responsibly disclosed in June with AnyDesk confirming and patching within days. This incident adds to AnyDesk's recent security troubles, which include a separate heap overflow fixed earlier in 2025 and a production system breach in early 2024.
Stay secure — stay Wavasec. 🔐