AnyDesk patched a pre-auth root flaw in silence. Now there's a working exploit.

A Czech researcher's thesis and a public proof-of-concept turn a quietly fixed AnyDesk bug into an urgent patching job for anyone still running old versions.

ThreatVectr NewsdeskAI-assistedPublished · Editor: Lee Brown· 4 min read
Illustration: a dim server room with a single Linux terminal window glowing on a monitor
Illustration made with AI. Not a photograph of the events described.
Share

Key points - A working exploit is now public for a pre-authentication remote code execution flaw in AnyDesk that lets an attacker take over a Linux machine as root before the user clicks Accept. - AnyDesk fixed the bug in its Linux client version 8.0.3 in June, but the changelog called it a crash fix with no CVE attached. - The flaw sits in how AnyDesk handles a user's profile image sent inside a UDP network packet during its Discovery feature, which looks for other AnyDesk clients on the same network. - The vulnerability was documented in a May 2025 Czech Technical University master's thesis by Vojtěch Krejsa before any public advisory appeared. - Anyone running an older AnyDesk client on a shared or office network should update immediately and check whether Discovery is switched on.

A remote takeover bug in AnyDesk, the popular remote-desktop tool used by IT teams and support desks, now has a fully working exploit in the wild.

On Linux, it hands an attacker root, the highest level of control on the machine, without the victim ever approving a connection.

The uncomfortable part is how it was handled. AnyDesk shipped the fix in June and described it in release notes as a crash bug. No CVE, no security advisory. The technical details came from an unexpected place: a university thesis. We've followed AnyDesk's security record since August, and the pattern of understating fixes isn't new.

What is the bug, in plain words?

AnyDesk has a feature called Discovery that lets clients find each other on the same local network, the way your laptop sees a printer. Part of that handshake includes a small user profile image sent inside a UDP packet, a type of network message that doesn't wait for a reply.

AnyDesk's code miscounts the size of that image. The miscount is an integer overflow, where a number wraps around past its maximum, leading to a heap-based buffer overflow: the program writes data into memory it wasn't supposed to touch. An attacker who controls what gets written there can run their own code.

On Linux, that code runs as root. No approval prompt, no password.

Which versions are fixed?

AnyDesk patched the issue across every platform it ships, but the version numbers suggest these weren't coordinated as a single security release.

Platform Fixed in
AnyDesk for Linux 8.0.3
AnyDesk for Windows 9.0.5
AnyDesk for macOS 9.0.1
AnyDesk for Android 8.0.0

The bug can also trigger during a standard connection between two AnyDesk clients, beyond the Discovery feature, which widens exposure past local networks.

Where did the exploit come from?

The technical writeup is inside a master's thesis published by Czech Technical University in Prague, authored by Vojtěch Krejsa in 2025, walking through the overflow and how to reach it.

The Hacker News reported this week that a full working exploit chain is now public, confirming pre-authentication root execution on Linux.

Should you worry about normal connections too?

Yes, because the bug isn't limited to Discovery. A specially crafted profile image can arrive during a routine session, so even teams that keep Discovery disabled aren't fully sheltered on unpatched installs.

What should affected users do?

Update AnyDesk on every machine that runs it. Linux is the most urgent case because the exploit requires no user interaction whatsoever, but Windows, macOS, iOS and Android are all affected and need the versions listed above.

If you manage AnyDesk across a fleet, check the AnyDesk Windows changelog and the equivalent per-platform notes, then disable Discovery on networks where it isn't needed. That alone shrinks the attack surface while patches roll out.

My read: the silent fix is the actual story. A pre-auth root bug in a tool that millions of support technicians install on other people's computers deserved a proper advisory in June. The exploit was always going to surface. It just did.

© 2026 Threat Vectr