What changed
The impact became clear after the update
In June, AnyDesk's Linux changelog described version 8.0.3 as fixing a bug that could cause a crash. V12 Security's newly published AnyPwn research gives that entry a different significance. Its proof of concept demonstrates command execution as root before connection approval against Linux 8.0.2, using a direct TCP connection to port 7070.
A remote-support service can receive network data before it decides whether to approve a session. That is why strong passwords and careful approval workflows do not, by themselves, address a flaw reachable before those checks. On Linux, the service normally runs as root, increasing the potential consequence of successful code execution.
Scope and limits
A demonstrated route is not every possible route
V12 says the vulnerable processing is reachable through AnyDesk relays, but its complete exploit demonstration is limited to direct TCP connections. The supplied offsets target a specific Linux 8.0.2 build and test environment, and an unsuccessful attempt can crash the service. These details should temper claims about other versions, relay exploitation or attacks in the wild.
Exploit code is not incident evidence
Defender workflow
Find the installation, then verify the fix
- 1
Inventory Linux installations. Include supplier-managed machines, temporary support deployments and golden images, not only centrally managed workstations.
- 2
Verify the running build. AnyDesk lists 8.0.3 as the corrected release and 8.1.0 as a later Linux release. Confirm the active service actually runs an updated build.
- 3
Check direct reachability. Review whether direct connections are enabled and exposed to untrusted networks. Account for custom listener ports and internal paths as well as internet access.
- 4
Investigate suspicious hosts. Where exposure and unusual behavior coincide, review service crashes, unexpected processes and network activity in the relevant time window. Preserve evidence before disruptive recovery steps when practical.
Defender note
A CVE is useful, but not required to begin
A security queue that accepts only CVE identifiers can miss credible issues like this one. Track the product, tested build, exposure, available correction and responsible owner. The endpoint is a verified record of which installations were updated, removed or left under a time-limited exception.
This topic came through a Cyber Security Hub newsletter. Threat Field Notes checked the researcher's published scope and AnyDesk's release history before writing this note.