Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 29 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:lizardsystems:terminal_services_manager:*:*:*:*:*:*:*:* |
Mon, 27 Apr 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lizardsystems
Lizardsystems terminal Services Manager |
|
| Vendors & Products |
Lizardsystems
Lizardsystems terminal Services Manager |
Thu, 23 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious input file with shellcode and jump instructions that overwrite the SEH handler pointer to execute calc.exe or other payloads when imported through the add computers wizard. | |
| Title | Terminal Services Manager 3.1 Buffer Overflow SEH | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-23T14:06:26.960Z
Reserved: 2026-04-22T11:21:22.260Z
Link: CVE-2018-25259
Updated: 2026-04-23T14:06:22.624Z
Status : Analyzed
Published: 2026-04-22T16:16:45.437
Modified: 2026-04-29T23:33:46.737
Link: CVE-2018-25259
No data.
OpenCVE Enrichment
Updated: 2026-04-27T19:55:00Z