
AnyDesk Linux 8.0.2 Heap Overflow Enables Pre-Auth Root RCE on Port 7070
AnyDesk Linux received a silent patch for a pre-auth root RCE in June 2024; researchers later published a working exploit showing the vendor minimized impact and omitted standard disclosure. The flaw’s relay reachability remains unconfirmed in public code, creating an ongoing blind spot for enterprise remote-desktop fleets.
The AnyPwn proof-of-concept targets mode-5 stream packets where 32-bit length arithmetic wraps when a payload of 0xFFFFFFF0 is declared, allocating a zero-byte buffer while recording the full size and enabling one-byte overflows into adjacent heap objects. The published ROP chain executes arbitrary commands as root; offsets are build-specific to 8.0.2 and the attack is probabilistic, requiring favorable heap layout or it crashes the service instead.
AnyDesk shipped the fix in 8.0.3 in June but listed only a generic crash fix in the changelog, assigned no CVE, and issued no advisory. The company stated the issue is limited to direct connections and unaffected platforms include Windows and macOS, yet researchers confirmed the same code path is reachable via relay servers using Frida instrumentation though the full chain was not completed.
This follows AnyDesk’s 2024 production-system breach that forced certificate revocations and parallels the earlier CVE-2025-27918 integer overflow fixed in 7.0.0. Removal of the 8.0.2 build from download servers immediately after the PoC video suggests deliberate suppression rather than routine maintenance.
Administrators should block TCP 7070 where possible and enforce 8.1.0 or later; the unresolved relay vector and absence of formal disclosure metrics indicate continued exposure for unpatched Linux deployments.
V12 Researchers: Public relay exploit chain released within 90 days
Sources (2)
- [1]The Hacker News(https://thehackernews.com/2026/10/researchers-publish-working-exploit-for.html)
- [2]V12 Security AnyPwn Release(https://github.com/v12security/anypwn)