Advisories
AnyDesk Remote‑Desktop Software Compromised: Source Code, Certificates Exfiltrated – CERT‑FR Alert
On 29 Jan 2024, France’s ANSSI notified that AnyDesk Software GmbH suffered a data breach. Source code, certificates and private keys may have been stolen, and two European relay servers were impacted. Versions of AnyDesk for Windows, macOS, Linux, Android, iOS, AppleTV and on‑premise clients before specific releases are potentially vulnerable to man‑in‑the‑middle or tampering attacks. CERT‑FR urges organisations to inventory installations, quarantine affected systems, verify legitimate use and monitor for abnormal activity.
Incident Overview
France’s ANSSI received a warning from Germany’s BSI on 29 January 2024 that AnyDesk Software GmbH had experienced a data breach. The leak could involve the company’s source code, digital certificates and private keys, and two European relay servers were also affected.
AnyDesk supplies remote‑desktop solutions for a wide range of platforms – Windows, macOS, Linux, Android, iOS, AppleTV, and on‑premise deployments – used for support, administration, tele‑work and internal resource access.
Affected Versions
- Windows installers and portable editions signed before 8.0.8 and 7.0.15
- macOS installers signed before 8.0.0
- Custom Windows clients not regenerated since 7.0.14 (on‑premise)
- Custom macOS clients not regenerated since 7.3.0 (on‑premise)
Other builds are under review; keep an eye on future updates.
Potential Threats
Exfiltrated credentials could enable:
- Man‑in‑the‑middle (MITM) attacks against AnyDesk traffic
- Tampering with AnyDesk binaries or updates
- Indirect entry points into corporate networks via compromised remote sessions
The CERT‑FR cannot confirm the feasibility of these attacks yet, but the risk warrants precaution.
Recommended Mitigation
- Inventory all systems for AnyDesk installations, including mobile devices.
- Quarantine any identified installations pending investigation.
- Verify that the use of AnyDesk aligns with approved internal policies.
- Assess the sensitivity of endpoints using the tool and apply stricter controls if needed.
Follow the CERT‑FR guidance on identifying and cataloguing AnyDesk usage for a thorough audit.
Next Steps
Stay tuned for further details from the vendor and ANSSI. Until then, treat any AnyDesk deployment as potentially compromised and enforce the above mitigations.