V12 Security was reported to have published its AnyPwn proof of concept on October 8, 2026. The PoC targets AnyDesk Linux 8.0.2 and demonstrates command execution as root over a direct TCP connection to port 7070 when the memory layout is favorable. Root is Linux’s highest-privilege account, so commands running with those permissions can affect the system broadly.
What AnyPwn demonstrates against AnyDesk Linux 8.0.2
The PoC specifies Linux x86_64 and AnyDesk’s anydesk --service mode. Its test machine ran Linux Mint 22.3 (Zena) with kernel 6.14.0-37-generic. The exploit offsets target AnyDesk Linux 8.0.2.
Why the memory layout matters
The flaw is in how AnyDesk handles a session packet. Its allocation calculation adds a 16-byte header to the declared payload length using unchecked 32-bit arithmetic. If that calculation wraps, the program can allocate a buffer that is too small even though the object retains a larger logical length.
The heap—the area of memory used for dynamically allocated objects—affects the outcome. When the target object is adjacent to the undersized buffer, the PoC can reach command execution as root. If the arrangement is unfavorable, the service can crash instead.
What V12 says about relay connections
V12 says a Frida trigger reached the vulnerable code path through AnyDesk relays. Its complete exploit demonstration, however, uses a direct TCP connection to port 7070; it did not demonstrate the full exploit through a relay.
The fixed release and later Linux listing
AnyDesk’s Linux changelog lists version 8.0.3 on June 23, 2026, with a generic fix for a bug that could lead to a crash. V12 identifies 8.0.3 as the version that fixes AnyPwn.
AnyDesk’s Linux download page lists version 8.1.0 as the latest release, with packages dated September 23, 2026.