Security researchers have published a fully working exploit for a pre-authentication, unauthenticated code execution vulnerability in AnyDesk for Linux that hands attackers root privileges before a connection is ever approved. Let that sink in: no user interaction, no session acceptance prompt, no credentials — just a network-reachable AnyDesk client and an attacker who knows the bug.
The most dangerous part of this story isn't the exploit itself. It's that AnyDesk patched the flaw in version 8.0.3 back in June, but the changelog described the fix only as "fixed a bug that could lead to a crash." No CVE was assigned. No security advisory was published. Which means your vulnerability scanners had nothing to key on, your asset inventory flagged nothing, and a substantial portion of your Linux fleet may still be running a remotely exploitable, root-yielding remote access client right now.
If your organization permits AnyDesk on Linux endpoints or servers — or if users have installed it without permission — treat this as an emergency patch cycle, not a routine one.
Technical Analysis
Affected Products and Platforms
| Attribute | Detail |
|---|---|
| Product | AnyDesk remote desktop client |
| Platform | Linux |
| Affected versions | All versions prior to 8.0.3 |
| Fixed version | AnyDesk 8.0.3 (released June 2026) |
| CVE | None assigned — vendor documented the fix as a crash bug |
| Access vector | Network, pre-authentication |
| Impact | Remote code execution as root |
| Exploitation status | Working public exploit published by researchers |
Why the "Crash Fix" Changelog Matters
This is a case study in silent patching, and it's a pattern defenders need to recognize. When a vendor assigns no CVE and describes an RCE as a stability fix, three failure modes cascade through your security program:
- Scanner blindness — Nessus, Qualys, and Tenable.io have no plugin to flag. Vulnerability management platforms that key on CVE/CPE data show the host as clean.
- Change-management friction — No security advisory means no justification for emergency patching. The update queues behind routine maintenance.
- Exposure persistence — EDR and asset tools rarely report installed AnyDesk versions on Linux, so nobody knows which hosts are vulnerable.
AnyDesk's daemon runs with elevated privileges on Linux because it must capture input and render sessions at the system level. That architectural reality is what turns a memory-handling bug in the client into a root shell. The attack surface is the AnyDesk service itself listening for inbound connections — historically on TCP/UDP port 7070 — meaning any host with the client installed and port reachable is a target, including servers, jump boxes, and developer workstations.
Attack Chain (Defender's View)
- Attacker scans for reachable AnyDesk Linux endpoints (port 7070, or targets identified via reconnaissance).
- Crafted traffic is sent to the AnyDesk service before any authentication or session approval handshake completes.
- The vulnerability is triggered in the pre-authentication code path, yielding code execution in the context of the AnyDesk daemon — root.
- Post-exploitation: attacker drops persistence (systemd units, cron, SSH keys), spawns shells as children of the AnyDesk process, and moves laterally.
Because exploitation happens pre-auth, the AnyDesk session approval prompt — the control most admins believe protects them — is never reached. Unattended access settings, whitelisting, and two-factor authentication on sessions do not mitigate this flaw. Only patching does.
Exploitation Status
- Working exploit code is public. Researchers released a full proof-of-concept, which collapses the window between disclosure and mass exploitation to days, not weeks.
- Remote access tooling is a perennial favorite for both ransomware affiliates and initial access brokers — AnyDesk in particular has a long history of abuse in intrusion chains. Expect rapid weaponization.
- At time of writing, no CVE has been assigned and the vendor advisory trail is thin, so you cannot rely on your vuln scanner to find this. You must hunt by installed version and process telemetry.
Detection & Response
The highest-fidelity detection strategy here is behavioral: a patched and healthy AnyDesk daemon should never spawn interactive shells, download tools, or execute scripting interpreters as root. Post-exploitation children of the AnyDesk process are a nearly zero-false-positive signal.
Sigma Rules
---
title: AnyDesk Linux Daemon Spawning Shell or Scripting Interpreter
id: 9c2b7f41-3e6a-4d58-b1f2-8a4c6d0e9b31
status: experimental
description: Detects the AnyDesk process on Linux spawning shells, interpreters, or download utilities — consistent with post-exploitation after the pre-auth root RCE disclosed for versions prior to 8.0.3.
references:
- https://thehackernews.com/2026/10/researchers-publish-working-exploit-for.html
- https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/10/15
tags:
- attack.execution
- attack.t1059.004
- attack.t1219
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- '/anydesk'
selection_child:
Image|endswith:
- '/bash'
- '/sh'
- '/dash'
- '/zsh'
- '/python'
- '/python3'
- '/perl'
- '/curl'
- '/wget'
- '/nc'
- '/ncat'
- '/netcat'
condition: selection_parent and selection_child
falsepositives:
- None expected — AnyDesk does not legitimately spawn shells or download utilities on Linux
level: critical
---
title: Suspicious Network Connection to AnyDesk Service Port 7070 from External Source
id: 4d8e1a92-6c3f-4b7d-9e21-5f0a3c8b6d47
status: experimental
description: Detects inbound network connections to the AnyDesk service port (7070) on Linux hosts from external or RFC1918-unexpected sources, which may indicate scanning or exploit delivery for the pre-auth AnyDesk Linux RCE.
references:
- https://thehackernews.com/2026/10/researchers-publish-working-exploit-for.html
- https://attack.mitre.org/techniques/T1190/
author: Security Arsenal
date: 2026/10/15
tags:
- attack.initial_access
- attack.t1190
- attack.t1219
logsource:
category: network_connection
product: linux
detection:
selection:
DestinationPort: 7070
Initiated: 'false'
filter_internal_ranges:
SourceIp|cidr:
- '10.0.0.0/8'
- '172.16.0.0/12'
- '192.168.0.0/16'
condition: selection and not filter_internal_ranges
falsepositives:
- Legitimate remote support sessions from external helpdesk vendors — baseline approved support source IPs and suppress them
level: high
---
title: Root-Owned Persistence Artifact Created Shortly After AnyDesk Process Start
id: 7f1c4e63-9b2a-4d85-a6c3-2e8d5f0b1a96
status: experimental
description: Detects creation of systemd units, cron entries, or authorized_keys modifications in root-owned paths on hosts where AnyDesk is installed — a common post-exploitation persistence step following root compromise via the AnyDesk Linux pre-auth RCE.
references:
- https://thehackernews.com/2026/10/researchers-publish-working-exploit-for.html
- https://attack.mitre.org/techniques/T1053/
- https://attack.mitre.org/techniques/T1543/
author: Security Arsenal
date: 2026/10/15
tags:
- attack.persistence
- attack.t1543.002
- attack.t1053.003
logsource:
category: file_event
product: linux
detection:
selection:
TargetFilename|contains:
- '/etc/systemd/system/'
- '/etc/cron.d/'
- '/var/spool/cron/'
- '/root/.ssh/authorized_keys'
condition: selection
falsepositives:
- Legitimate package installation and configuration management (Ansible, Puppet) — correlate with deployment windows and management host source activity
level: high
KQL — Microsoft Sentinel / Defender
This query hunts across both native Defender for Endpoint Linux telemetry and Syslog/CEF-ingested Linux process events for AnyDesk spawning post-exploitation tooling, plus external connections to port 7070.
let suspicious_children = dynamic(["/bin/bash", "/bin/sh", "/usr/bin/curl", "/usr/bin/wget", "/usr/bin/python3", "/bin/nc", "/usr/bin/ncat"]);
union isfuzzy=true
(
DeviceProcessEvents
| where InitiatingProcessFileName =~ "anydesk"
| where ProcessCommandLine has_any ("bash", "sh -", "curl", "wget", "python", "nc ", "ncat")
or FileName has_any ("bash", "sh", "curl", "wget", "python3", "nc", "ncat")
| project TimeGenerated, DeviceName, AccountName, FileName, ProcessCommandLine, InitiatingProcessCommandLine, Source="MDE"
),
(
Syslog
| where ProcessName =~ "anydesk" or SyslogMessage has "anydesk"
| where SyslogMessage has_any ("bash", "/bin/sh", "curl", "wget", "python", "ncat")
| project TimeGenerated, Computer, ProcessName, SyslogMessage, Source="Syslog"
)
| order by TimeGenerated desc;
// Correlate with inbound connections to AnyDesk service port from non-internal sources
DeviceNetworkEvents
| where LocalPort == 7070 and ActionType == "InboundConnectionAccepted"
| where not(RemoteIP startswith "10." or RemoteIP startswith "192.168." or RemoteIP startswith "172.16.")
| summarize ConnectionCount=count(), FirstSeen=min(TimeGenerated), LastSeen=max(TimeGenerated) by DeviceName, RemoteIP, InitiatingProcessFileName
| order by ConnectionCount desc;
Velociraptor VQL — Fleet Hunt
Use this artifact across your Linux fleet to simultaneously (a) inventory AnyDesk versions below 8.0.3 and (b) surface live suspicious children of the AnyDesk daemon.
-- AnyDesk Linux exposure and compromise hunt
-- 1) Identify installed AnyDesk versions below the 8.0.3 fix
-- 2) Enumerate anydesk processes and their children for post-exploitation behavior
LET packages = SELECT Name, Version
FROM deb_packages()
WHERE Name =~ 'anydesk'
LET anydesk_procs = SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Name =~ 'anydesk' OR Exe =~ 'anydesk'
LET suspicious_kids = SELECT Pid, Ppid, Name, Exe, CommandLine, Username, CreateTime
FROM pslist()
WHERE Ppid IN (SELECT Pid FROM anydesk_procs)
AND Exe =~ '(bash|/sh$|curl|wget|python|perl|nc|ncat)'
SELECT 'package_inventory' AS Finding, Name AS Detail1, Version AS Detail2, '' AS Detail3 FROM packages
UNION ALL
SELECT 'anydesk_process' AS Finding, str(str=Pid) AS Detail1, Exe AS Detail2, CommandLine AS Detail3 FROM anydesk_procs
UNION ALL
SELECT 'SUSPICIOUS_CHILD' AS Finding, str(str=Pid) AS Detail1, Exe AS Detail2, CommandLine AS Detail3 FROM suspicious_kids
Remediation & Verification Script (Bash)
Run via your configuration management tooling (Ansible, Salt, or a remote execution platform) across all Linux hosts. It inventories AnyDesk, reports vulnerable versions, upgrades to the current release, and flags post-exploitation indicators for follow-up IR.
#!/bin/bash
# AnyDesk Linux Pre-Auth Root RCE — verification and remediation
# Patched version: 8.0.3 (June 2026). All prior versions are exposed.
FIXED_MAJOR=8
FIXED_MINOR=0
FIXED_PATCH=3
echo "=== AnyDesk Exposure Check: $(hostname) ==="
if ! command -v anydesk >/dev/null 2>&1; then
echo "[OK] AnyDesk not installed. No action required."
exit 0
fi
VERSION=$(anydesk --version 2>/dev/null | grep -oE '[0-9]+\.[0-9]+\.[0-9]+' | head -1)
if [ -z "$VERSION" ]; then
VERSION=$(dpkg -s anydesk 2>/dev/null | grep '^Version:' | awk '{print $2}' | grep -oE '[0-9]+\.[0-9]+\.[0-9]+' | head -1)
fi
echo "[*] Detected AnyDesk version: ${VERSION:-UNKNOWN}"
IFS='.' read -r VMAJ VMIN VPAT <<< "$VERSION"
VULN=false
if [ -z "$VMAJ" ]; then
echo "[WARN] Version undetermined — treat as VULNERABLE and reinstall latest."
VULN=true
elif [ "$VMAJ" -lt "$FIXED_MAJOR" ]; then
VULN=true
elif [ "$VMAJ" -eq "$FIXED_MAJOR" ] && [ "$VMIN" -eq 0 ] && [ "$VPAT" -lt "$FIXED_PATCH" ]; then
VULN=true
fi
if [ "$VULN" = true ]; then
echo "[VULNERABLE] AnyDesk $VERSION < 8.0.3 — pre-auth root RCE exposed. Upgrading..."
# Stop the service first to break any active malicious sessions
systemctl stop anydesk 2>/dev/null
if command -v apt-get >/dev/null 2>&1; then
apt-get update -qq && apt-get install -y --only-upgrade anydesk || \
wget -qO /tmp/anydesk-latest.deb https://download.anydesk.com/linux/anydesk_amd64.deb && \
dpkg -i /tmp/anydesk-latest.deb && apt-get -f install -y
elif command -v dnf >/dev/null 2>&1; then
dnf upgrade -y anydesk || dnf install -y https://download.anydesk.com/linux/anydesk-latest.rpm
elif command -v yum >/dev/null 2>&1; then
yum update -y anydesk
fi
systemctl start anydesk 2>/dev/null
NEWVER=$(anydesk --version 2>/dev/null | grep -oE '[0-9]+\.[0-9]+\.[0-9]+' | head -1)
echo "[*] Post-upgrade version: $NEWVER"
else
echo "[OK] AnyDesk $VERSION is at or above 8.0.3."
fi
echo "=== Post-Exploitation Indicator Sweep ==="
# Suspicious children of anydesk process
AD_PID=$(pgrep -x anydesk | head -1)
if [ -n "$AD_PID" ]; then
ps --ppid "$AD_PID" -o pid,ppid,user,comm,args | grep -Ei 'bash|sh$|curl|wget|python|perl|nc |ncat' && \
echo "[ALERT] Suspicious child process under anydesk — initiate IR." || \
echo "[OK] No suspicious children of anydesk."
fi
# Recently modified persistence locations
echo "[*] Persistence artifacts modified in last 30 days (review manually):"
find /etc/systemd/system /etc/cron.d /var/spool/cron /root/.ssh/authorized_keys -mtime -30 2>/dev/null
# Exposed listener check
echo "[*] AnyDesk listener exposure:"
ss -tulpn 2>/dev/null | grep -i anydesk || echo "[OK] No anydesk listener bound."
echo "=== Check Complete ==="
Remediation
- Patch immediately — AnyDesk 8.0.3 or later on every Linux host. Download from the official vendor site: https://anydesk.com/en/downloads/linux. Do not wait for a CVE or a scanner plugin; neither may ever arrive for this fix.
- Inventory first. Your vuln scanner will not find this. Query your package manager fleet-wide (
dpkg -l | grep anydesk,rpm -qa | grep anydesk) or deploy the script above via Ansible/Salt to enumerate installed versions. - Remove AnyDesk where it isn't sanctioned. Remote access tooling outside IT control is an unauthorized initial-access vector. If the business need doesn't exist, uninstall it — don't just patch it.
- Block AnyDesk service traffic at the perimeter where feasible. If remote support is handled through an approved gateway, deny unsolicited inbound TCP/UDP 7070 at the edge and restrict AnyDesk connectivity to known support source IPs.
- Hunt retroactively. Because exploit code is now public and versions below 8.0.3 have been exposed since before June, run the Sigma/KQL/VQL detections above against historical telemetry going back at least 90 days. Look specifically for root shells parented to anydesk, unexpected authorized_keys changes, and new systemd units.
- Treat exposed internet-facing hosts as potentially compromised. Any Linux host running AnyDesk <8.0.3 with port 7070 reachable from untrusted networks should get a full IR triage — credential rotation, persistence audit, and memory capture if indicators surface.
- Add silent-patch detection to your vuln management process. Subscribe to researcher disclosure feeds and vendor changelog monitoring, not just CVE feeds. This incident is a textbook case where NVD-derived intelligence would have left you blind.
Conclusion
The AnyDesk Linux flaw is dangerous twice: once as a pre-auth root RCE with public exploit code, and again as a patch the vendor deliberately obscured. Defenders who rely solely on CVE-driven vulnerability management are exposed right now and don't know it. Close the gap with version-based inventory, behavioral detection on the AnyDesk daemon, and an honest assessment of whether remote access tooling belongs on your Linux estate at all.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.