Intrusion Prevention

LANDesk.Management.Suite.Alert.Service.Buffer.Overflow

Description

This vulnerability is in LANDesk Management Suite. It could be exploited by attackers to remotely take complete control of an affected system. The issue is caused by a stack overflow error in the Alert Service (Aolnsrvr.exe) that fails to properly handle malformed data sent to port 65535/UDP, which could be exploited by remote unauthenticated attackers to execute arbitrary commands with SYSTEM privileges.

Affected Products

LANDesk Management Suite version 8.7 and prior.

Impact

System compromise.

Recommended Actions

Upgrade to the latest Service Pack and apply hotfix INST-11050687.2 :
http://kb.landesk.com/al/12/4/article.asp?aid=4142&tab=search&bt=4

CVE References

CVE-2007-1674