What Is the Target of the anydesk-printer-com-impersonation-poc Vulnerability?

The anydesk-printer-com-impersonation-poc proof-of-concept targets the AnyDesk for Windows service (version 9.7.6) that runs as LocalSystem, exploiting a COM impersonation flaw in the printer IPC pipe \\.\pipe\adprinterpipe to escalate privileges to NT AUTHORITY\SYSTEM.

The anydesk-printer-com-impersonation-poc vulnerability, published in the bikini/exploitarium repository, demonstrates a high-severity local privilege escalation (LPE) against AnyDesk's Windows implementation. This exploit specifically abuses the printer worker component's handling of marshalled COM objects over a named pipe, allowing attackers to impersonate the service account.

Understanding the anydesk-printer-com-impersonation-poc Target

AnyDesk Windows Service Running as LocalSystem

According to the source analysis in anydesk-printer-com-impersonation-poc/README.md lines 17–20, AnyDesk installs its service using CreateServiceW with a NULL service-account argument. This configuration forces the service to execute under the LocalSystem account (NT AUTHORITY\SYSTEM), granting the process the highest privilege level on the Windows host.

The PoC leverages this default permission model. Because the service handles printer-related IPC requests while holding SYSTEM privileges, a low-privileged local attacker can coerce the service into executing arbitrary code under its security context.

The Vulnerable Printer IPC Pipe

The attack vector centers on the named pipe \\.\pipe\adprinterpipe. As documented in README.md lines 5–6 and 33–35, the AnyDesk service creates this pipe to facilitate printer functionality. The vulnerability exists in the printer worker routine that:

  1. Accepts a marshalled COM object from the pipe
  2. Unmarshals the object using standard COM APIs
  3. Invokes IStream::Read with the impersonation level set to RPC_C_IMP_LEVEL_IMPERSONATE

This sequence allows the attacker's process to impersonate the token of the calling thread—effectively becoming SYSTEM.

Technical Breakdown of the Vulnerability

COM Object Unmarshalling and Impersonation

The exploit abuses the COM marshalling infrastructure. When the AnyDesk service unmarshalls an object provided by an attacker-controlled client, it implicitly uses the security context of the service itself. By crafting a malicious COM object and writing it to \\.\pipe\adprinterpipe, the attacker triggers the service to execute CoUnmarshalInterface and subsequently call IStream::Read under impersonation.

As implemented in bikini/exploitarium, the PoC demonstrates that the service accepts external input on this pipe without adequate validation of the caller's privileges. The poc.py script automates the creation of this malicious payload and the subsequent token impersonation.

Affected Version: AnyDesk 9.7.6

The anydesk-printer-com-impersonation-poc specifically targets AnyDesk version 9.7.6, the release in which the issue was originally discovered (README.md lines 7–11). While later versions may have patched this vulnerability, the PoC remains valid against unpatched installations of this specific build.

How to Verify the Vulnerability

The bikini/exploitarium repository provides two primary methods to verify the presence of this vulnerability: a dynamic self-test and static binary analysis.

Running the Self-Test

The self-test simulates both attacker and victim processes on the same host to confirm the impersonation primitive works:


# Install Python dependencies

python -m pip install -r requirements.txt

# Execute the PoC self-test

python poc.py selftest

Successful execution yields output confirming the impersonated identity:


[attacker]
PROBE_IMPERSONATED=DOMAIN\User
[victim]
VICTIM_READ_COMPLETE

This demonstrates that the attacker process successfully captured a token impersonating the victim (SYSTEM) context.

Static Marker Analysis

To verify if a specific AnyDesk binary contains the vulnerable code paths without executing the full exploit:


# Analyze the AnyDesk executable for vulnerability markers

python poc.py analyze "C:\Program Files\AnyDesk\AnyDesk.exe"

The tool checks for four critical markers and outputs JSON results:

{
  "markers": {
    "pipe_name_utf16": true,
    "iid_iunknown": true,
    "iid_istream": true,
    "co_unmarshal_import": true
  }
}

When all markers return true, the binary contains the pipe creation logic (pipe_name_utf16), the required COM interface identifiers (iid_iunknown, iid_istream), and the unmarshalling import (co_unmarshal_import), confirming it is vulnerable to the anydesk-printer-com-impersonation-poc attack.

Key Source Files in bikini/exploitarium

The repository contains three essential components that document and implement the exploit:

Summary

  • The anydesk-printer-com-impersonation-poc targets the AnyDesk Windows service running as LocalSystem, specifically version 9.7.6.
  • The vulnerability resides in the printer IPC pipe (\\.\pipe\adprinterpipe) handling code.
  • Attackers exploit COM impersonation via IStream::Read with RPC_C_IMP_LEVEL_IMPERSONATE to gain SYSTEM privileges.
  • The bikini/exploitarium PoC provides both dynamic self-tests and static binary analysis to verify vulnerable installations.
  • Successful exploitation allows low-privileged users to escalate to NT AUTHORITY\SYSTEM.

Frequently Asked Questions

What specific component of AnyDesk is vulnerable to the anydesk-printer-com-impersonation-poc?

The vulnerable component is the printer worker within the AnyDesk service process. This worker creates the named pipe \\.\pipe\adprinterpipe and handles incoming connections by unmarshalling COM objects and invoking IStream::Read with impersonation privileges enabled.

Does the anydesk-printer-com-impersonation-poc work on the latest version of AnyDesk?

The PoC was specifically developed and tested against AnyDesk version 9.7.6. While the underlying vulnerability pattern (COM impersonation over named pipes) may exist in other versions, the specific markers and offsets in the provided poc.py target this particular release. Users should upgrade to the latest AnyDesk version and verify that the vendor has patched the COM impersonation logic.

How does the anydesk-printer-com-impersonation-poc achieve privilege escalation?

The exploit achieves privilege escalation by impersonating the LocalSystem token. When a low-privileged attacker writes a crafted COM object to the printer pipe, the AnyDesk service (running as SYSTEM) unmarshals it and calls IStream::Read with RPC_C_IMP_LEVEL_IMPERSONATE. This causes the service thread to temporarily adopt the attacker's security context, but because the service holds primary token privileges, the attacker can reverse the impersonation to capture a SYSTEM token for their own process.

What permissions are required to run the anydesk-printer-com-impersonation-poc?

An attacker requires only standard local user privileges to execute the PoC. The exploit does not require administrative rights because the vulnerable named pipe (\\.\pipe\adprinterpipe) is designed to accept connections from any local user, and the COM marshalling occurs within the context of the already-elevated AnyDesk service process.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →