LANDesk.Management.Suite.Alert.Service.Buffer.Overflow

description-logoDescription

This vulnerability is in LANDesk Management Suite. It could be exploited by attackers to remotely take complete control of an affected system. The issue is caused by a stack overflow error in the Alert Service (Aolnsrvr.exe) that fails to properly handle malformed data sent to port 65535/UDP, which could be exploited by remote unauthenticated attackers to execute arbitrary commands with SYSTEM privileges.

affected-products-logoAffected Products

LANDesk Management Suite version 8.7 and prior.

Impact logoImpact

System compromise.

recomended-action-logoRecommended Actions

Upgrade to the latest Service Pack and apply hotfix INST-11050687.2 :

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)