VYPR

Terminal Services Manager

by Lizardsystems

CVEs (2)

  • CVE-2018-25259HigApr 22, 2026
    risk 0.55cvss 8.4epss 0.00

    Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious input file with shellcode and jump instructions that overwrite the SEH handler pointer to execute calc.exe or other payloads when imported through the add computers wizard.

  • CVE-2019-25545MedMar 21, 2026
    risk 0.40cvss 6.2epss 0.00

    Terminal Services Manager 3.2.1 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string in the computer name field. Attackers can input a 5000-byte buffer of data into the 'Computer name or IP address' field during computer addition, causing a denial of service when the server entry is accessed.