vendor:
Terminal Services Manager
by:
Alejandra Sánchez
7.8
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Terminal Services Manager
Affected Version From: 3.2.1
Affected Version To: 3.2.1
Patch Exists: YES
Related CWE: N/A
CPE: //a:lizardsystems:terminal_services_manager:3.2.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2019
Terminal Services Manager 3.2.1 – Local Buffer Overflow Denial of Service
Terminal Services Manager 3.2.1 is vulnerable to a local buffer overflow denial of service attack. By creating a malicious file containing a large number of 'A' characters and pasting the contents of the file into the 'Computer name or IP address' field, an attacker can cause a denial of service condition.
Mitigation:
Ensure that Terminal Services Manager is updated to the latest version and that all users are aware of the potential risks of buffer overflow attacks.