Lizardsystems Vulnerabilities and Affected Products
Vulnerabilities associated with Terminal Services Manager.
Products
Clear product- LanSpy2 vulnerabilities
- Terminal Services Manager2 vulnerabilities
- LanSend1 vulnerability
- Remote Desktop Audit1 vulnerability
- Remote Process Explorer1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-25259HIGH | Terminal Services Manager 3.1 Buffer Overflow SEHTerminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious input file with shellcode and jump instructions that overwrite the SEH handler pointer to execute calc.exe or other payloads when imported through the add computers wizard. CWE-306Apr 22, 2026 | CVSS8.6v4.0 | EPSS0.189% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-25545MEDIUM | Terminal Services Manager 3.2.1 Local Buffer Overflow Denial of ServiceTerminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string in the computer name field. Attackers can input a 5000-byte buffer of data into the 'Computer name or IP address' field during computer addition, causing a denial of service when the server entry is accessed. CWE-787Mar 21, 2026 | CVSS6.9v4.0 | EPSS0.191% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |