CVE-2005-0353

Sentinel License Manager 7.2.0.2 - Remote Code Execution via UDP Port 5093 Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 3 public exploits for CVE-2005-0353. PoCs published by Metasploit, class101, hdm, including Metasploit module exploits/windows/license/sentinel_lm7_udp.

AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in SentinelLM via a maliciously crafted UDP packet sent to port 5093. It leverages SEH overwrites and a jump-back technique to execute arbitrary payloads, targeting multiple Windows versions.

Description

Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to execute arbitrary code by sending a large amount of data to UDP port 5093.

Exploits (3)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16746

This Metasploit module exploits a stack buffer overflow in SentinelLM via a maliciously crafted UDP packet sent to port 5093. It leverages SEH overwrites and a jump-back technique to execute arbitrary payloads, targeting multiple Windows versions.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SentinelLM 7.2.0.0
No auth needed
Prerequisites: Network access to UDP port 5093 · Target running vulnerable SentinelLM service
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by class101 · cremotewindows
https://www.exploit-db.com/exploits/875

This exploit targets a stack overflow vulnerability in SentinelLM's UDP License Service (CVE-2005-0353). It sends a crafted UDP packet to port 5093, triggering a buffer overflow to execute shellcode for remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SentinelLM version 7.*
No auth needed
Prerequisites: Network access to the target's UDP port 5093 · Target running SentinelLM version 7.*
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
by hdm · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/license/sentinel_lm7_udp.rb

This Metasploit module exploits a stack buffer overflow in Sentinel License Manager via a maliciously crafted UDP packet. It leverages SEH overwrite and a jump-back technique to execute arbitrary payloads, targeting multiple Windows versions.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Sentinel License Manager 7.2.0.0
No auth needed
Prerequisites: Network access to UDP port 5093 · Target running vulnerable SentinelLM version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/12742
Mailing List mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=111072872816405&w=2
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/14511
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/19621
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=111022094326772&w=2
Patch, Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/108790
Exploit, Patch, Vendor Advisory x_refsource_misc
http://www.cirt.dk/advisories/cirt-30-advisory.pdf

Scores

EPSS 0.7113
EPSS Percentile 99.3%

Details

Status published
Products (1)
safenet/sentinel_license_manager 7.2_.0.2
Published May 02, 2005
Tracked Since Feb 18, 2026