The AnyDesk Exploit That Lets Hackers In Before You Even Click Accept

·
Listen to this article~4 min
The AnyDesk Exploit That Lets Hackers In Before You Even Click Accept

Researchers published a working exploit for a pre-auth AnyDesk Linux flaw that grants root access before you approve the connection. AnyDesk patched it quietly in 8.0.3 with no CVE.

Security researchers just dropped a working exploit for a nasty pre-auth flaw in AnyDesk on Linux. It gives attackers root access before anyone approves the connection. That's not a typo. Before you click accept, before you even see a prompt, someone could already be inside your system. AnyDesk patched it in version 8.0.3 back in June. But here's where it gets weird. The changelog just said "fixed a bug that could lead to a crash." No CVE. No security advisory. Nothing that would make you sit up and pay attention. And honestly, that's the part that bugs me the most. ### What Actually Happened Let me break this down without the jargon. AnyDesk is remote desktop software. You install it, someone else connects to your machine, and they can control it like they're sitting right there. Super handy for IT support or helping your parents fix their Wi-Fi from three states away. But this flaw? It's a pre-authentication remote code execution. Translation: an attacker doesn't need your password. They don't need you to approve anything. They just need to reach the service, and boom, they've got root. Root means they own the machine. Full control. Game over. ### Why the Quiet Patch Matters Here's what I keep coming back to. When a company patches a critical security hole but describes it as a crash fix, users don't know to update urgently. They think, "Eh, a crash. I'll get to it." But this wasn't a crash. This was a door left wide open. - No CVE assigned, so vulnerability scanners couldn't flag it - No security advisory, so admins had no heads-up - The changelog wording downplayed the severity I'm not saying it was intentional. But I am saying it left a lot of people exposed longer than necessary. ### What You Should Do Right Now First, check your AnyDesk version. If you're on anything below 8.0.3, update immediately. Don't wait. Don't finish your coffee first. Second, if you're running AnyDesk on Linux servers, think hard about whether you need it exposed to the internet at all. A lot of folks install it for convenience and forget it's listening for connections. Third, and this is the big one, don't rely on vendor changelogs as your only security news source. Follow security researchers. Watch for exploit publications. Because sometimes the most dangerous bugs get the quietest fixes. > "The most dangerous vulnerability isn't the one with a flashy name. It's the one nobody told you about." ### The Bigger Picture This isn't just an AnyDesk problem. It's a pattern. Companies patch things quietly to avoid panic, avoid bad press, avoid the headache. And I get it. But security through obscurity doesn't work when researchers publish working exploits. The exploit is out there now. Anyone with moderate skills can use it. So if you've been putting off that update, this is your sign. Update. Check your exposure. And maybe set a reminder to review your remote access tools every few months. Your future self will thank you.