CVE-2018-25259
8.4LizardSystems · Terminal Services Manager
Terminal Services Manager 3.1 contains a stack-based buffer overflow in the computer names field, which allows local attackers to achieve arbitrary code execution via crafted input files.
Executive summary
A stack-based buffer overflow vulnerability in LizardSystems Terminal Services Manager 3.1 allows a local attacker to execute arbitrary code with elevated privileges.
Vulnerability
The application is susceptible to a stack-based buffer overflow in the computer names field, which can be triggered when processing a malicious input file during the add computers wizard. While the vulnerability is local, it does not require authentication to trigger once the user interacts with the vulnerable import function.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the host system. Given the CVSS score of 8.4, this represents a high-severity risk that could lead to a full system compromise, unauthorized data access, or the deployment of further malicious payloads. The impact is particularly significant if the software is run by administrative users, as the attacker would inherit those permissions.
Remediation
Immediate Action: There is no official patch provided by the vendor; users should immediately discontinue the use of Terminal Services Manager 3.1 and remove the software from all systems.
Proactive Monitoring: Security teams should monitor endpoint logs for unexpected process execution or abnormal behavior originating from the Terminal Services Manager process.
Compensating Controls: Restrict execution of the application using endpoint protection policies or application whitelisting to prevent unauthorized users from launching the vulnerable binary.
Exploitation status
Public Exploit Available: Yes, a functional local exploit exists, as documented in the Exploit-DB entry (EDB-ID 46058).
Analyst recommendation
Given the availability of a functional exploit and the lack of a vendor-supplied patch, this software should be considered insecure for use in any production environment. Organizations must identify and uninstall all instances of Terminal Services Manager 3.1 to eliminate this risk entirely.
More LizardSystems CVEs
Sources
Originally found and disclosed by bzyo, per the CVE Program record.
- ExploitDB-46058 Exploit / PoC
- Official Product Homepage
- VulnCheck Advisory: Terminal Services Manager 3.1 Buffer Overflow SEH Third-party advisory