Application security, Endpoint/Device Security

AnyDesk Linux exploit grants root access before connection approval

Linux

A pre-authentication remote code execution flaw in AnyDesk for Linux has been fully exploited, allowing attackers to gain root access without user approval. Security researchers published a working exploit for the vulnerability, which AnyDesk patched in version 8.0.3 in June. The fix was not clearly disclosed, with the changelog only mentioning a bug fix for crashes, and no CVE was initially assigned, as first reported by The Hacker News.

The exploit, dubbed AnyPwn, targets a heap buffer overflow in AnyDesk's session protocol, specifically affecting direct TCP connections on port 7070. While the exploit is probabilistic and requires specific heap layouts, researchers demonstrated its potential reachability through AnyDesk's relay servers. AnyDesk stated that Windows and macOS are not affected, and the vulnerability is limited to direct Linux connections. The flaw works by manipulating packet handling to cause a buffer overflow, allowing an attacker to inject commands and execute them with root privileges. Administrators are urged to update AnyDesk Linux to at least version 8.0.3 or restrict access to TCP port 7070. This incident follows a previous security breach of AnyDesk's production systems in early 2024.

Source: The Hacker News

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds