Critical AnyDesk Linux Flaw Exploited for Root Access
A recently disclosed pre-authentication vulnerability in AnyDesk for Linux allows attackers to gain root access without user approval. Although patched, the initial fix lacked proper disclosure.
TL;DR
- Researchers released a working exploit for a critical AnyDesk Linux RCE flaw.
- The vulnerability allows unauthenticated attackers to gain root access remotely.
- AnyDesk addressed the issue in version 8.0.3 but initially downplayed its severity.
- No CVE was assigned at the time of patching, raising concerns over transparency.
- Organizations using AnyDesk on Linux should verify they're running version 8.0.3 or later.
Security researchers have revealed a fully functional exploit targeting a serious vulnerability in AnyDesk's Linux client. The flaw enables remote attackers to execute arbitrary code with root privileges even before a connection is approved by the user. This poses a significant risk to organizations relying on AnyDesk for remote support or access.
While AnyDesk issued a patch in June with version 8.0.3, the company described the underlying issue vaguely as “a bug that could lead to a crash.” At that time, neither a CVE identifier nor detailed security advisory was published, which has drawn criticism from the security community regarding responsible disclosure practices.
Vulnerability Overview
- The flaw affects AnyDesk’s Linux client prior to version 8.0.3.
- It allows pre-authentication remote code execution with root privileges.
- Attackers do not require user interaction or approval to exploit it.
- Exploitation leads to full system compromise.
- No CVE number was initially assigned despite the severity.
Patch and Disclosure Concerns
- Version 8.0.3 fixed the issue but did not publicly acknowledge its security implications.
- The official changelog only mentioned 'fixed a bug that could lead to a crash.'
- Security experts criticized the lack of a CVE or public advisory at the time of patching.
- A full exploit has now been made public, increasing urgency for users to update.
- Organizations are advised to audit their AnyDesk deployments and enforce updates immediately.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.