A Critical Linux Vulnerability Has Been Exploited, Putting Thousands of Systems at Risk
Researchers have published a working exploit for a previously unknown vulnerability in the AnyDesk remote desktop software on Linux systems. The flaw allows attackers to gain root access without authentication, giving them complete control over affected machines.
The vulnerability affects all versions of AnyDesk up to 7.1.0 and is present on any system running Linux with the software installed. This means that thousands of organizations and individuals who rely on remote desktop connections for work or other purposes are at risk of being compromised. The exploit, which has been made publicly available by the researchers, demonstrates just how easy it is to gain unauthorized access to sensitive systems.
The AnyDesk vulnerability works by exploiting a weakness in the way the software handles socket creation. When an attacker connects to a vulnerable system using AnyDesk, they can create a new socket that allows them to bypass authentication and execute arbitrary code with root privileges. This is particularly concerning because it doesn’t require any user interaction or specific conditions to be met – once connected, the attacker has full access to the system.
The publication of this exploit raises questions about the responsibility of researchers in revealing vulnerabilities. While their intentions may be pure, making such exploits publicly available can inadvertently aid malicious actors in carrying out attacks. This highlights the delicate balance between transparency and security, which is a constant challenge for cybersecurity professionals.
This vulnerability also underscores the importance of maintaining up-to-date software on all systems, particularly those that provide remote access to sensitive data or infrastructure. Organizations and individuals using AnyDesk should immediately review their setup and ensure they are running the latest version of the software. Users can take steps to mitigate the risk by enabling two-factor authentication, limiting network access, and monitoring system logs for suspicious activity.
Ultimately, this exploit serves as a reminder that even seemingly secure systems can be vulnerable to exploitation if not properly maintained or configured. By staying informed about potential threats and taking proactive measures, individuals and organizations can reduce their exposure to cyber risks and stay ahead of attackers.
Source: The Hacker News — 2026-10-09