Executive brief
Motex LANSCOPE Endpoint Manager, a tool used by organizations to manage and secure corporate devices, contains a critical security flaw. An attacker can remotely take control of managed computers by sending malicious network traffic to the software's client or detection agents. This vulnerability is currently being exploited in the wild, posing a significant risk of unauthorized data access or complete system takeover.
Technical details
The vulnerability (CWE-940) exists in the On-Premises version of Motex LANSCOPE Endpoint Manager, specifically affecting the Client program (MR) and Detection agent (DA). The software fails to properly verify the origin of incoming communication requests. A remote, unauthenticated attacker can exploit this by sending specially crafted network packets to the affected components. Successful exploitation allows for arbitrary code execution with high impact on confidentiality, integrity, and availability. This flaw is confirmed to be exploited in the wild and has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog.
Affected products
- Motex LANSCOPE Endpoint Manager (On-Premises) Versions up to 9.3.2.7, 9.3.3.0 to 9.3.3.9, 9.4.0.0 to 9.4.0.5, 9.4.1.0 to 9.4.1.5, 9.4.2.0 to 9.4.2.6, 9.4.3.0 to 9.4.3.8, 9.4.4.0 to 9.4.4.6, 9.4.5.0 to 9.4.5.4, 9.4.6.0 to 9.4.6.3, and 9.4.7.0 to 9.4.7.1
Timeline
- 2025-10-20: disclosed: Initial disclosure by JPCERT/CC and Motex
- 2025-10-22: kev added: Added to CISA Known Exploited Vulnerabilities catalog
- 2025-10-22: exploited: Confirmed active exploitation in the wild