CVE-2018-25259 is a stack-based buffer overflow vulnerability affecting Terminal Services Manager version 3.1, located in the computer names input field. An attacker can exploit this flaw by crafting a malicious input file containing shellcode that overwrites the structured exception handling (SEH) pointer, allowing arbitrary code execution such as launching calc.exe or other payloads through the add computers wizard functionality. The vulnerability is classified as HIGH severity with a CVSS score of 8.4, as it requires only local access with no authentication or user interaction needed, presents low attack complexity, and provides complete compromise of confidentiality, integrity, and availability. The attack vector is local only, which limits its exposure but does not diminish the critical nature of potential impact on affected systems. This vulnerability is not currently being actively exploited in the wild, as evidenced by its absence from the CISA Known Exploited Vulnerabilities (KEV) catalog and inactive status on the Hot List. The EPSS probability score of 0.00012 indicates minimal likelihood of exploitation, and community attention remains limited. However, organizations running Terminal Services Manager 3.1 should implement appropriate access controls and consider upgrading to mitigate this locally exploitable threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.1CPE matchmatch criteria | cpe:2.3:a:lizardsystems:terminal_services_manager:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.