Science & Tech · Cybersecurity · 3 hrs ago

AnyDesk Linux flaw allowed attackers to gain root access without approval

AnyDesk Linux flaw allowed attackers to gain root access without approval

A security flaw in AnyDesk for Linux allowed attackers to run commands with the highest system privileges, called root access.

They could do this before a user approved a connection.

The flaw affected direct Linux connections using TCP port 7070.

Researchers published a working exploit, named AnyPwn, although it depends on specific conditions and may not work every time.

AnyDesk said Windows and macOS are not affected.

The company fixed the issue in Linux version 8.0.3 in June, but the change was not clearly described in its notes.

Administrators should update to at least that version or restrict access to port 7070.

Sources

Related news