hacker-news · Crawled Oct 9, 2026

Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access

3 IoCs
Read original article ↗

AI Summary

Security researchers have published a working exploit called AnyPwn for a pre-authentication remote code execution vulnerability in AnyDesk Linux versions prior to 8.0.3. The flaw is a heap buffer overflow in the session protocol that allows attackers to achieve root access via direct TCP connections on port 7070. The exploit relies on a 32-bit integer overflow when calculating buffer size, leading to a heap-based buffer overflow that corrupts adjacent memory and enables arbitrary code execution using a ROP chain. Although AnyDesk patched the issue in June 2026, no CVE has been assigned and no formal advisory was issued.

AI-extracted · verify before operational use

Indicators of Compromise 3 extracted

Type Value Detail
IP 7070 Details →
Filename AnyPwn Details →
GitHub Repo V12/AnyPwn Details →