AnyDesk Linux Flaw Lets Remote Attackers Execute Code as Root Without Authentication
A critical unauthenticated remote code execution (RCE) vulnerability in AnyDesk for Linux versions up to 8.0.2 allows attackers to execute arbitrary commands as root without any user interaction. Dubbed “AnyPwn,” this zero-click vulnerability affects systems with TCP port 7070 exposed to untrusted networks. A proof-of-concept exploit is publicly available, significantly increasing exploitation risk. Organizations must immediately upgrade to AnyDesk 8.0.3, audit network exposure, and review system logs for potential compromise indicators.
Introduction
Remote desktop software has become a critical component of modern IT infrastructure, enabling remote work and system administration across enterprises worldwide. However, when vulnerabilities emerge in these widely-deployed tools, the security implications can be severe.
AnyDesk, one of the most popular remote desktop applications with over 170 million users globally, recently disclosed a critical vulnerability affecting its Linux client. This flaw represents a worst-case security scenario: unauthenticated remote code execution with root privileges, requiring zero user interaction.
The vulnerability, tracked internally and nicknamed “AnyPwn” by researchers, allows remote attackers to completely compromise affected Linux systems. With a working proof-of-concept now circulating in the security community, the window for opportunistic attacks has narrowed considerably.
Background & Context
AnyDesk operates by establishing connections between client systems through its proprietary protocol, typically listening on TCP port 7070 for incoming connections. The software is designed to facilitate remote desktop access with minimal configuration, making it popular among IT administrators, help desk personnel, and remote workers.
The Linux version of AnyDesk runs with elevated privileges to provide full system access capabilities during remote sessions. This architectural design decision, while functional, creates a high-value target for attackers seeking system-level access.
This vulnerability surfaces approximately one year after AnyDesk experienced a significant security incident in February 2024, where the company confirmed unauthorized access to its production systems. That incident forced a complete security overhaul, including code signing certificate revocations and mandatory password resets.
The remote desktop software market has repeatedly demonstrated that these applications present attractive attack surfaces. Similar critical vulnerabilities have affected competitors like TeamViewer, LogMeIn, and other remote access tools, often with devastating consequences when exploited at scale.
Technical Breakdown
The AnyPwn vulnerability exists in AnyDesk’s connection handling mechanism prior to authentication. When the AnyDesk service receives specially crafted network packets on port 7070, it processes certain requests before validating the sender’s credentials.
The flaw allows an attacker to inject malicious commands into the processing pipeline. Because AnyDesk runs with root privileges on Linux systems, any code execution automatically inherits these elevated permissions.
The vulnerability chain works as follows:
- Attacker identifies a target running vulnerable AnyDesk versions (up to 8.0.2)
- Attacker sends crafted packets to TCP port 7070
- AnyDesk processes these packets before authentication checks
- Malicious payload executes with root privileges
- Attacker gains complete system control
The proof-of-concept exploit demonstrates command injection, allowing attackers to:
# Create backdoor user
useradd -m -s /bin/bash -G sudo backdoor
# Establish persistence
echo "@reboot /tmp/.hidden/backdoor.sh" | crontab -
# Exfiltrate sensitive data
tar -czf /tmp/data.tar.gz /etc/shadow /root/.ssh /home/*/.ssh
What makes this vulnerability particularly dangerous is the zero-click nature. Unlike phishing-dependent attacks or vulnerabilities requiring user interaction, AnyPwn can be exploited silently while users remain completely unaware.
The attack vector doesn’t require existing AnyDesk sessions or connections. If port 7070 is accessible from the attacker’s network position, the system is vulnerable.
Impact & Risk Assessment
The severity of this vulnerability cannot be overstated. It represents a complete system compromise scenario with several aggravating factors:
Severity: Critical (CVSS Score: Expected 9.8-10.0)
Attack Complexity: Low – Exploitation requires only network access to port 7070 and the publicly available proof-of-concept.
Privileges Required: None – The vulnerability is unauthenticated, requiring no prior access or credentials.
User Interaction: None – This is a zero-click vulnerability requiring no user actions.
Scope: Changed – Attackers gain root access, far exceeding the privileges of typical AnyDesk operations.
Organizations face multiple risk scenarios:
Enterprise Environments: IT departments frequently deploy AnyDesk across server infrastructure for remote management. A single vulnerable system could provide attackers with a foothold for lateral movement.
Cloud Infrastructure: Linux systems in cloud environments often have AnyDesk installed for emergency access. If security groups misconfigure port exposure, these systems become immediate targets.
Managed Service Providers: MSPs using AnyDesk for client management could face cascading compromises across their entire client base.
Data Centers: Physical or virtual servers running AnyDesk for out-of-band management become high-value targets for ransomware operators and advanced persistent threat actors.
The availability of proof-of-concept code dramatically accelerates the exploitation timeline. History shows that critical RCE vulnerabilities with public exploits typically see widespread exploitation attempts within 48-72 hours of disclosure.
Vendor Response
AnyDesk has released version 8.0.3 for Linux, which addresses this critical vulnerability. The patch was released in coordination with security researchers who responsibly disclosed the flaw.
The vendor’s security advisory confirms the vulnerability affects all Linux versions prior to 8.0.3 and strongly recommends immediate updating. AnyDesk has implemented additional input validation and authentication checks in the patched version to prevent exploitation.
AnyDesk’s response timeline appears appropriate given the severity, with patches available concurrent with public disclosure. This approach minimizes the window of vulnerability while ensuring users have immediate access to fixes.
The vendor has not disclosed whether this vulnerability was discovered through internal security audits, external research, or active exploitation in the wild. No evidence of pre-disclosure exploitation has been confirmed at this time.
Mitigations & Workarounds
Organizations unable to immediately patch should implement these emergency mitigations:
Immediate Actions:
- Network Isolation – Block external access to TCP port 7070:
# Using iptables
iptables -A INPUT -p tcp --dport 7070 -s 0.0.0.0/0 -j DROP
iptables -A INPUT -p tcp --dport 7070 -s [trusted_network] -j ACCEPT
# Using ufw
ufw deny 7070/tcp
ufw allow from [trusted_network] to any port 7070
- Service Termination – Stop AnyDesk service on non-essential systems:
systemctl stop anydesk
systemctl disable anydesk- Update to Version 8.0.3:
# Download and install latest version
wget https://download.anydesk.com/linux/anydesk_8.0.3-1_amd64.deb
sudo dpkg -i anydesk_8.0.3-1_amd64.debLong-term Mitigations:
- Implement network segmentation to restrict AnyDesk access to management VLANs
- Deploy VPN requirements for all remote desktop access
- Enable firewall rules limiting port 7070 to known-good IP addresses
- Consider alternative remote access solutions with better security postures for internet-facing systems
Detection & Monitoring
Security teams should immediately begin hunting for potential exploitation attempts and indicators of compromise:
Network Detection:
Monitor for unusual connections to TCP port 7070:
# Review established connections
netstat -antp | grep :7070
# Check for suspicious connection patterns in logs
journalctl -u anydesk | grep -E "connection|error|failed"
Log Analysis:
Examine AnyDesk logs for authentication anomalies:
# Review AnyDesk logs
cat /var/log/anydesk/*.log | grep -E "command|exec|shell"
# Check system authentication logs
grep anydesk /var/log/auth.log
Compromise Indicators:
- Unexpected user accounts created
- New SSH keys in authorized_keys files
- Unusual cron jobs or systemd timers
- Outbound connections to suspicious IP addresses
- File modifications in sensitive directories (/etc, /root, /home)
SIEM Integration:
Configure alerts for:
- Multiple failed or successful connections to port 7070 from external IPs
- AnyDesk process spawning unusual child processes
- Privilege escalation events coinciding with AnyDesk activity
Best Practices
Organizations should implement these security practices to reduce remote desktop software risks:
Access Control:
- Never expose remote desktop software directly to the internet
- Require VPN or jump host access for all remote administration
- Implement zero-trust network architecture principles
Vulnerability Management:
- Subscribe to vendor security advisories for all remote access tools
- Establish emergency patching procedures for critical infrastructure software
- Maintain asset inventory of all systems running remote desktop software
Defense in Depth:
- Deploy endpoint detection and response (EDR) solutions
- Enable application whitelisting where possible
- Implement network segmentation between management and production networks
- Use principle of least privilege for service accounts
Monitoring and Response:
- Establish baseline behavior for remote desktop connections
- Configure real-time alerts for anomalous access patterns
- Conduct regular security audits of remote access configurations
- Maintain incident response playbooks for remote access compromises
Key Takeaways
- AnyDesk Linux versions up to 8.0.2 contain a critical unauthenticated RCE vulnerability allowing root access
- The vulnerability requires zero user interaction and has publicly available proof-of-concept code
- Immediate upgrade to version 8.0.3 is mandatory for all Linux deployments
- Organizations must audit network exposure of TCP port 7070 and restrict access to trusted networks only
- Security teams should review logs for potential compromise indicators dating back several weeks
- Remote desktop software should never be directly exposed to the internet without additional security controls
- This incident reinforces the critical importance of rapid patch deployment for internet-facing services
References
- AnyDesk Official Security Advisory
- AnyDesk Download Page: https://anydesk.com/en/downloads/linux
- AnyDesk Version 8.0.3 Release Notes
- Linux Security Best Practices Documentation
- CVE Database (pending assignment)
Stay updated at https://cydhaal.com — Your Daily Dose of Cyber Intelligence.
📧 Subscribe to our newsletter at https://cydhaal.com/newsletter/