Description
A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or execute arbitrary code.
Published: 2025-08-29
Score: 9.3 Critical
EPSS: 1.1% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-26268 A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or potentially result in arbitrary code execution.
History

Mon, 03 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or potentially result in arbitrary code execution. A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or execute arbitrary code.
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Tue, 02 Sep 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 02 Sep 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Netsupport
Netsupport netsupport Manager Agent
Netsupport netsupport Manager Client
Netsupportsoftware
Netsupportsoftware netsupport Manager
Vendors & Products Netsupport
Netsupport netsupport Manager Agent
Netsupport netsupport Manager Client
Netsupportsoftware
Netsupportsoftware netsupport Manager

Sat, 30 Aug 2025 13:00:00 +0000


Fri, 29 Aug 2025 23:45:00 +0000

Type Values Removed Values Added
Description A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or potentially result in arbitrary code execution.
Title NetSupport Manager < 14.12.0000 Heap-Based Buffer Overflow
Weaknesses CWE-122
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Netsupport Netsupport Manager Agent Netsupport Manager Client
Netsupportsoftware Netsupport Manager
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-05-14T02:07:51.245Z

Reserved: 2025-04-15T19:15:22.566Z

Link: CVE-2025-34164

cve-icon Vulnrichment

Updated: 2025-09-02T19:24:55.673Z

cve-icon NVD

Status : Deferred

Published: 2025-08-30T00:15:30.770

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-34164

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-09-02T15:23:30Z

Weaknesses