Vulnerabilities & Exploits

AnyDesk Linux exploit reaches root over port 7070

A public exploit for AnyDesk Linux 8.0.2 went online October 8, and it shows pre-authentication code execution as root before any session approval. AnyDesk had already shipped 8.0.3 in June, but it described the fix as a crash bug and gave it no CVE or formal advisory.

The proof of concept abuses a heap buffer overflow in the session protocol. In plain terms, a crafted packet corrupts memory in the connection handler well enough to steer the service into running an attacker command, and the published code works over direct TCP connections on port 7070.

That puts the exposure on AnyDesk Linux hosts reachable on that path, not just on users who click through a session prompt. Because the exploit is build-specific and probabilistic, it is not a universal one-shot, but any exposed 8.0.2 system is still a candidate for root compromise rather than a mere crash.

1 source · 6h ago

Timeline

Sources

Part of the PlainSec briefing for 2026-10-09

Every edition of this story: AnyDesk Linux exploit reaches root over port 7070

More from today