Threat reportVulnerabilityTL-2026-3153
Working Public Exploit ("AnyPwn") for Pre-Auth AnyDesk Linux Heap Overflow Yielding Root Access
Working Public Exploit ("AnyPwn") for Pre-Auth AnyDesk Linux (TL-2026-3153), also tracked as AnyPwn, is a high-severity software vulnerability, first published 2026-10-09. It has no confirmed attribution, affects AnyDesk Software GmbH AnyDesk (Linux client/service), references 1 CVE (CVE-2025-27918), maps to 10 MITRE ATT&CK techniques (T1021, T1046, T1059.004), and is covered by 9 detection rules and 13 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 1Referenced vulnerabilities
- Techniques
- 10MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 13Indicators of compromise
Key facts for TL-2026-3153
- Threat ID
- TL-2026-3153
- Also known as
- AnyPwn
- Severity
- HIGH
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, managed-service-providers, government administration, finance, health, critical-infrastructure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 13
- Updates
- 2026-10-09 · revalidated 1× · latest source
Malware and tooling in Working Public Exploit ("AnyPwn") for Pre-Auth AnyDesk Linux
Malware and tooling: AnyDesk, AnyPwn
How Working Public Exploit ("AnyPwn") for Pre-Auth AnyDesk Linux works
V12 Security published a working exploit named AnyPwn on GitHub on 2026-10-08 for a pre-authentication heap buffer overflow in the AnyDesk Linux session protocol's mode-5 stream packet handler, achieving command execution as root over direct TCP connections to port 7070. The exploit is probabilistic and specific to AnyDesk Linux build 8.0.2; the defect is fixed in 8.0.3, and Windows and macOS clients are not affected.
AnyDesk for Linux versions up to and including 8.0.2 contain a pre-authentication heap buffer overflow in the mode-5 stream packet handler of the session protocol (reported by researcher Rick de Jager of the V12 Security team). The handler derives the size of its backing heap allocation from an attacker-controlled declared payload length plus a fixed 16-byte object header, using unchecked 32-bit integer arithmetic. An attacker-chosen declared length near the top of the 32-bit range causes this sum to wrap to a very small value, so the handler allocates a tiny buffer (0-15 bytes) while continuing to treat the original, much larger declared length as the amount of attacker data to copy into it, corrupting adjacent heap memory. AnyPwn weaponizes this by first heap-spraying roughly 100 persistent objects across a range of size classes (approximately 0x1 to 0x17f1 bytes) over parallel connections to normalize heap layout and increase the odds that the undersized allocation lands adjacent to a chosen victim object, then triggers the overflow to corrupt that object. A second, ROP-oriented spray phase allocates about twenty 0xf000-byte objects containing gadget-sled payloads to increase the chance that corrupted pointers/data are redirected into attacker-supplied code reuse chains, enabling arbitrary command execution running as root -- all before the connecting session is approved by a user on the target. Exploitation requires no authentication and no user interaction beyond the service listening on TCP/7070, but is probabilistic: if the overwritten object is not adjacent to the corrupted buffer, or heap layout otherwise does not match expectations, the AnyDesk service process simply crashes (denial of service) rather than yielding code execution, and offsets are build-specific to the tested 8.0.2 Linux binary (SHA-256 62ee04ad48dc039dd9c927f998e56143c87a9c5e12d28654f78c7f6340394f5a on a Linux Mint 22.3 / kernel 6.14.0-37-generic test target); other builds require different offset values and were not demonstrated by the public PoC. V12 Security privately reported the issue to AnyDesk on 2026-06-22; AnyDesk acknowledged on 2026-06-23 and shipped a fix in version 8.0.3 in June 2026 without a public security advisory, and later pulled the 8.0.2 installer from its download page once the PoC was published. No CVE has been assigned to this flaw as of 2026-10-09; it is distinct from the previously disclosed CVE-2025-27918, an unrelated integer-overflow/heap-overflow in AnyDesk's identity user-image/Discovery-feature handling (fixed across platforms in versions released around April 2025, including Linux 7.0.0), which the source article mentions only for contrast. The public exploit release (2026-10-08) and subsequent reporting (The Hacker News, 2026-10-09) state no confirmed in-the-wild exploitation of this specific flaw; the primary near-term risk is opportunistic scanning and exploitation of internet- or network-reachable AnyDesk Linux TCP/7070 listeners now that a working PoC and crash/RCE methodology are public. Vendor- and researcher-recommended mitigation is to upgrade to AnyDesk Linux 8.0.3 or later and, where immediate patching is not possible, to restrict network reachability of TCP/7070 to trusted hosts only.
MITRE ATT&CK techniques used in TL-2026-3153
Lateral Movement
Discovery
T1046 Network Service Discovery
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell; T1203 Exploitation for Client Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application
Impact
Persistence
T1505 Server Software Component
Resource Development
Affected products and versions in Working Public Exploit ("AnyPwn") for Pre-Auth AnyDesk Linux
- AnyDesk Software GmbH — AnyDesk (Linux client/service)
Vulnerable versions: 8.0.2; 8.0.1 and earlier (unconfirmed per source)
Fixed in: 8.0.3; 8.1.0 (latest, supersedes fix)
Remediation for Working Public Exploit ("AnyPwn") for Pre-Auth AnyDesk Linux
Patches
- Upgrade AnyDesk Linux to version 8.0.3 or later (fix released June 2026)
Immediate actions
- Restrict network access to AnyDesk Linux TCP/7070 to trusted/management hosts only via firewall or security group rules
- Inventory all Linux hosts running AnyDesk and identify any still on 8.0.2 or earlier
- Remove or disable the AnyDesk Linux service on internet-facing hosts where remote access is not strictly required
Workarounds
- Firewall TCP/7070 so only trusted administrative networks can reach the AnyDesk Linux listener
- Temporarily stop the AnyDesk service on Linux hosts where it is not actively required until patched
Longer-term hardening
- Deploy EDR/host monitoring for anomalous child processes spawned by the AnyDesk service (ad_svc) running as root
- Establish a patch-management SLA for remote-access/remote-support software given its historically high-value attack-surface profile
- Network-segment remote-access tooling away from sensitive infrastructure
CVEs associated with Working Public Exploit ("AnyPwn") for Pre-Auth AnyDesk Linux
Weaknesses (CWE) in Working Public Exploit ("AnyPwn") for Pre-Auth AnyDesk Linux
Timeline of Working Public Exploit ("AnyPwn") for Pre-Auth AnyDesk Linux
- Unrelated prior AnyDesk flaw CVE-2025-27918 (identity/user-image heap overflow) patched across platforms, including Linux 7.0.0; cited by reporting only for contrast with the new mode-5 issue.
- Rick de Jager of V12 Security privately reports the AnyDesk Linux mode-5 stream packet heap overflow to AnyDesk.
- AnyDesk acknowledges the report.
- AnyDesk ships a fix in Linux client/service version 8.0.3 (June 2026), without a public security advisory.
- Additional security-blog coverage (Undercode Testing) describes the flaw's exposure scope and urges patch verification.
- AnyDesk removes the 8.0.2 Linux installer from its public download page following PoC publication.
- V12 Security publishes the AnyPwn working exploit on GitHub (v12-security/pocs, anydesk directory), targeting AnyDesk Linux 8.0.2.
- AnyDesk states the vulnerability as exploited is limited to direct connections on Linux, not relay-mediated sessions; V12 showed via Frida that the trigger reaches the handler over relays but did not demonstrate full RCE there.
- The Hacker News publishes coverage of the AnyPwn exploit, surfacing it to the broader security community.
Update history for TL-2026-3153
- 2026-10-09 — AnyPwn: AnyDesk Linux 8.0.2 Pre-Authentication Heap Buffer Overflow Enables Remote Root Code Execution: What changed No field escalation. The newer report rates the issue CRITICAL, but that is an assessment, not new evidence; exploitability stays POC_PUBLIC and no in-the-wild exploitation is reported. New indicators (4) 4 behavioral indicator
Sources cited for Working Public Exploit ("AnyPwn") for Pre-Auth AnyDesk Linux
Detection coverage for TL-2026-3153
As of 2026-10-09, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-3153 across Splunk SPL, Microsoft KQL and Sigma, covering 13 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.