# Working Public Exploit ("AnyPwn") for Pre-Auth AnyDesk Linux Heap Overflow Yielding Root Access

> V12 Security published a working exploit named AnyPwn on GitHub on 2026-10-08 for a pre-authentication heap buffer overflow in the AnyDesk Linux session protocol's mode-5 stream packet handler, achieving command execution as root over direct TCP connections to port 7070. The exploit is probabilistic and specific to AnyDesk Linux build 8.0.2; the defect is fixed in 8.0.3, and Windows and macOS clients are not affected.

- **Published:** 2026-10-09T00:00:00Z
- **Last reviewed:** 2026-10-09T22:02:31.902Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3153
- **ID:** TL-2026-3153
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 13 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-27918

## Description

AnyDesk for Linux versions up to and including 8.0.2 contain a pre-authentication heap buffer overflow in the mode-5 stream packet handler of the session protocol (reported by researcher Rick de Jager of the V12 Security team). The handler derives the size of its backing heap allocation from an attacker-controlled declared payload length plus a fixed 16-byte object header, using unchecked 32-bit integer arithmetic. An attacker-chosen declared length near the top of the 32-bit range causes this sum to wrap to a very small value, so the handler allocates a tiny buffer (0-15 bytes) while continuing to treat the original, much larger declared length as the amount of attacker data to copy into it, corrupting adjacent heap memory. AnyPwn weaponizes this by first heap-spraying roughly 100 persistent objects across a range of size classes (approximately 0x1 to 0x17f1 bytes) over parallel connections to normalize heap layout and increase the odds that the undersized allocation lands adjacent to a chosen victim object, then triggers the overflow to corrupt that object. A second, ROP-oriented spray phase allocates about twenty 0xf000-byte objects containing gadget-sled payloads to increase the chance that corrupted pointers/data are redirected into attacker-supplied code reuse chains, enabling arbitrary command execution running as root -- all before the connecting session is approved by a user on the target. Exploitation requires no authentication and no user interaction beyond the service listening on TCP/7070, but is probabilistic: if the overwritten object is not adjacent to the corrupted buffer, or heap layout otherwise does not match expectations, the AnyDesk service process simply crashes (denial of service) rather than yielding code execution, and offsets are build-specific to the tested 8.0.2 Linux binary (SHA-256 62ee04ad48dc039dd9c927f998e56143c87a9c5e12d28654f78c7f6340394f5a on a Linux Mint 22.3 / kernel 6.14.0-37-generic test target); other builds require different offset values and were not demonstrated by the public PoC. V12 Security privately reported the issue to AnyDesk on 2026-06-22; AnyDesk acknowledged on 2026-06-23 and shipped a fix in version 8.0.3 in June 2026 without a public security advisory, and later pulled the 8.0.2 installer from its download page once the PoC was published. No CVE has been assigned to this flaw as of 2026-10-09; it is distinct from the previously disclosed CVE-2025-27918, an unrelated integer-overflow/heap-overflow in AnyDesk's identity user-image/Discovery-feature handling (fixed across platforms in versions released around April 2025, including Linux 7.0.0), which the source article mentions only for contrast. The public exploit release (2026-10-08) and subsequent reporting (The Hacker News, 2026-10-09) state no confirmed in-the-wild exploitation of this specific flaw; the primary near-term risk is opportunistic scanning and exploitation of internet- or network-reachable AnyDesk Linux TCP/7070 listeners now that a working PoC and crash/RCE methodology are public. Vendor- and researcher-recommended mitigation is to upgrade to AnyDesk Linux 8.0.3 or later and, where immediate patching is not possible, to restrict network reachability of TCP/7070 to trusted hosts only.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1203 Exploitation for Client Execution
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1505 Server Software Component
- T1046 Network Service Discovery
- T1021 Remote Services
- T1489 Service Stop
- T1588 Obtain Capabilities
- T1133 External Remote Services
- T1068 Exploitation for Privilege Escalation

## Sources

- [Researchers Publish Working Exploit for Pre-Auth AnyDesk Linux Flaw That Gives Root Access](https://thehackernews.com/2026/10/researchers-publish-working-exploit-for.html)
- [v12-security/pocs - anydesk (AnyPwn PoC)](https://github.com/v12-security/pocs/tree/main/anydesk)
- [NVD - CVE-2025-27918](https://nvd.nist.gov/vuln/detail/CVE-2025-27918)
- [AnyPwn: The AnyDesk Pre-Auth RCE Coverage](https://undercodetesting.com/anypwn-the-anydesk-pre-auth-0-click-rce-that-exposes-10-million-endpoints-are-you-patched-video/)
- [CVE-2025-27918 Detail](https://www.sentinelone.com/vulnerability-database/cve-2025-27918/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3153
