Executive brief
A vulnerability exists in the Landesk Management Suite, a platform used by IT departments to manage and secure corporate devices. An attacker can send a specially crafted network packet to the system to cause a crash or potentially take full control of the server. This could lead to a total service outage or the theft of sensitive organizational data.
Technical details
A stack-based buffer overflow vulnerability exists in the collector.exe component of Landesk Management Suite (now Ivanti). The flaw is located in the network listener service, which fails to properly validate the size of incoming packets before copying data into a fixed-size memory buffer. A remote, unauthenticated attacker can exploit this by sending a large, specially crafted packet over the network. Successful exploitation can lead to a denial-of-service (DoS) condition through a service crash or the execution of arbitrary code with the privileges of the collector.exe process.
Affected products
- Landesk Management Suite 10.0.0.271 and earlier
- Ivanti Management Suite 10.0.0.271 and earlier
Timeline
- 2017-01-23: advisory: NVD publication date