Science & Tech · Cybersecurity · 3 hrs ago
AnyDesk Linux flaw allowed attackers to gain root access without approval
A security flaw in AnyDesk for Linux allowed attackers to run commands with the highest system privileges, called root access.
They could do this before a user approved a connection.
The flaw affected direct Linux connections using TCP port 7070.
Researchers published a working exploit, named AnyPwn, although it depends on specific conditions and may not work every time.
AnyDesk said Windows and macOS are not affected.
The company fixed the issue in Linux version 8.0.3 in June, but the change was not clearly described in its notes.
Administrators should update to at least that version or restrict access to port 7070.
A fully exploited flaw in AnyDesk for Linux allowed attackers to gain root access without user approval.
Researchers published a working exploit, dubbed AnyPwn, targeting a heap buffer overflow in AnyDesk’s session protocol.
AnyDesk patched the flaw in version 8.0.3 in June, but the fix was not clearly described in the changelog.
The vulnerability affects direct Linux connections, including connections using TCP port 7070; Windows and macOS are not affected.
Administrators are urged to update AnyDesk Linux to at least version 8.0.3 or restrict access to TCP port 7070.
- Who
- Attackers could exploit the flaw; security researchers published a working exploit.
- What
- A pre-authentication flaw allowed attackers to execute commands with root privileges without user approval.
- When
- The flaw was patched in June; the article was published on 2026-10-11.
- Where
- AnyDesk for Linux, affecting direct connections over TCP port 7070.
- Why
- Not stated
This story does not have two clearly opposing sides.
No direct quotes in the coverage so far.
AnyDesk patched the flaw in version 8.0.3.
SC Media reported that researchers had published a working exploit for the flaw.
- Affected product
- AnyDesk for Linux
- Exploit name
- AnyPwn
- Vulnerability type
- Heap buffer overflow in the session protocol
- Affected connection
- Direct TCP connections on port 7070
- Patched version
- AnyDesk Linux 8.0.3











