NetSupport Manager 0-Day Vulnerabilities Enable Remote Code Execution
ID: ec51c455-e031-5c88-9d4a-623cb805e824
STIX ID: report--ec51c455-e031-5c88-9d4a-623cb805e824
Feed Name: GBHackers
Two critical unauthenticated zero-day vulnerabilities in NetSupport Manager's undocumented broadcast feature (CVE-2025-34164 — heap-based OOB write via integer overflow; CVE-2025-34165 — stack-based OOB read) allow attackers to leak memory, bypass ASLR, achieve arbitrary memory writes and ultimately remote code execution; researchers demonstrated a complete exploitation chain targeting widely deployed instances in industrial/OT networks. NetSupport released fixes in version 14.12.0000 (29 July 2025); interim mitigations include enforcing network segmentation, restricting TCP port 5405, and monitoring for suspicious broadcast protocol activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
