Critical AnyDesk Linux Flaw Lets Remote Attackers Execute Code as Root
Key Takeaways A critical heap buffer overflow vulnerability (AnyPwn) has been identified in AnyDesk for Linux. The flaw, CVE-2023-44023, allows unauthenticated, remote code execution with root...
Key Takeaways
- A critical heap buffer overflow vulnerability (AnyPwn) has been identified in AnyDesk for Linux.
- The flaw, CVE-2023-44023, allows unauthenticated, remote code execution with root privileges.
- AnyDesk Linux versions 8.0.2 and earlier are affected.
- The issue has been patched in AnyDesk Linux 8.0.3.
- Organizations should update immediately and restrict access to TCP port 7070.
A severe vulnerability in AnyDesk for Linux, designated AnyPwn, allows remote attackers to execute arbitrary code with root privileges without requiring authentication or user interaction. A working proof-of-concept (PoC) for this critical flaw has been publicly released, underscoring the urgency for immediate patching.
Table Of Content
The vulnerability, which affects AnyDesk Linux versions 8.0.2 and older, has been addressed in version 8.0.3. Cybersecurity teams managing Linux environments where AnyDesk is deployed are strongly advised to update their installations promptly and to verify network configurations to ensure TCP port 7070 is not exposed to untrusted networks.
The discovery of this flaw is attributed to Rick de Jager of the V12 security team, leveraging their AI-powered security review platform. V12 initially disclosed the issue in June, characterizing it as a pre-authentication, zero-click remote code execution vulnerability stemming from a heap buffer overflow.
AnyDesk acknowledged the report swiftly, releasing the 8.0.3 update within days of the initial disclosure in June. However, the public release of exploit code on October 8 has reignited concerns, highlighting the ongoing risk to systems that have yet to implement the necessary updates.
Understanding the AnyDesk Linux Flaw
According to technical documentation published by V12 Security, the root cause of this vulnerability lies within AnyDesk’s session protocol. This protocol is responsible for managing data exchange during a remote client’s connection to the service.
Heap Buffer Overflow Explained
In the vulnerable versions, the mode-5 stream packet handler processes a remote payload length without sufficient validation. The software then adds a 16-byte object header to this value using 32-bit arithmetic. A maliciously crafted length value can cause this arithmetic operation to wrap around, leading the application to allocate a significantly smaller memory region than required, while still interpreting it as a much larger object.
This discrepancy creates an out-of-bounds write condition. Essentially, an attacker can send a small network packet that tricks AnyDesk into expecting a massive amount of data. The vulnerable service then attempts to write attacker-controlled data beyond the confines of the undersized allocated memory area. Such an action can corrupt adjacent memory objects and, under specific circumstances, hijack program execution. Researchers have demonstrated that this vulnerability can be leveraged to execute arbitrary commands through the AnyDesk service.
Severity and Impact
The security implications are profound because the AnyDesk service typically operates with root privileges on Linux systems. Root access represents the highest level of control within the operating system, granting an attacker complete authority over files, processes, user accounts, and security configurations. A successful exploit of this flaw could provide an attacker with a formidable foothold on the compromised host, even before any desktop-sharing request is accepted by a legitimate user. This characteristic distinguishes the AnyPwn vulnerability from many other remote-support risks that commonly necessitate stolen credentials, user approval, or pre-configured unattended access passwords.
The publicly released exploit specifically targets AnyDesk Linux 8.0.2 running in service mode on x86_64 architectures. It establishes a direct connection to TCP port 7070 and relies on a particular memory layout, which means successful exploitation is not guaranteed in every instance. If the memory layout is unsuitable, the service might crash instead of executing the attacker’s command. Furthermore, the published exploit uses offsets tailored for the exact vulnerable build, indicating that it does not universally prove exploitability for all AnyDesk Linux versions.
Network Exposure Considerations
Regarding network exposure, AnyDesk initially stated that the vulnerability was limited to direct Linux connections and did not impact Windows or macOS platforms. However, the V12 researchers reported successfully reaching the vulnerable code path via AnyDesk relay connections during their testing using a Frida-based approach. While they did not fully demonstrate the complete root-code-execution chain through these relays, direct exposure of TCP/7070 remains the confirmed primary risk vector, with full relay-based exploitation still under investigation.
The disclosure of this vulnerability also underscores the persistent security challenges associated with remote-access software. Such tools are frequently installed on high-value servers and are widely trusted by IT professionals. This incident adds to a history of security concerns surrounding remote management tools, which, even when legitimate, can become vectors for persistent access following an initial compromise.
What You Should Do
- Update AnyDesk: Immediately upgrade all AnyDesk for Linux installations to version 8.0.3 or later.
- Restrict Network Access: If immediate patching is not feasible, restrict inbound access to TCP port 7070 at all network boundaries, including firewalls, VPN gateways, and cloud security groups.
- Monitor Logs: Review AnyDesk service logs for any suspicious activity, look for unexpected root-level processes, and monitor outbound connections from systems that may have exposed TCP/7070.
- Review Changelogs: While AnyDesk’s Linux changelog described the fix as addressing a bug that could lead to a crash, understand that this entry corresponds to the critical security vulnerability discussed.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.