Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-25259

27
FAUCET Score

CVE-2018-25259 is a stack-based buffer overflow vulnerability affecting Terminal Services Manager version 3.1, located in the computer names input field. An attacker can exploit this flaw by crafting a malicious input file containing shellcode that overwrites the structured exception handling (SEH) pointer, allowing arbitrary code execution such as launching calc.exe or other payloads through the add computers wizard functionality. The vulnerability is classified as HIGH severity with a CVSS score of 8.4, as it requires only local access with no authentication or user interaction needed, presents low attack complexity, and provides complete compromise of confidentiality, integrity, and availability. The attack vector is local only, which limits its exposure but does not diminish the critical nature of potential impact on affected systems. This vulnerability is not currently being actively exploited in the wild, as evidenced by its absence from the CISA Known Exploited Vulnerabilities (KEV) catalog and inactive status on the Hot List. The EPSS probability score of 0.00012 indicates minimal likelihood of exploitation, and community attention remains limited. However, organizations running Terminal Services Manager 3.1 should implement appropriate access controls and consider upgrading to mitigate this locally exploitable threat.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.1CPE matchmatch criteria
cpe:2.3:a:lizardsystems:terminal_services_manager:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 4.0

8.6HIGH

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
LOCAL
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.19%
Probability of exploitation in next 30 days
EPSS Percentile
8.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0019 is in the 13th percentile among its peer group of 3,237 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

lizardsystems.com
Product
exploit-db.com / exploits/46058
ExploitVDB Entry
vulncheck.com / advisories/terminal-services-manager-buffer-overflow-seh
Third Party Advisory