Executive brief
Lansweeper lsrunase and lsencrypt are tools used to encrypt and run applications with specific credentials. A security flaw in these tools allows anyone with access to an encrypted password string to instantly recover the original password in plain text. This could lead to unauthorized access to administrative accounts or other sensitive systems where these credentials are used.
Technical details
Lansweeper lsrunase 2.0 and lsencrypt 2.0 utilize a weak cryptographic scheme to protect credentials. The tools use RC4 encryption where the key is derived from a 20-byte SHA-1 hash of a 150-byte buffer. This buffer consists of an 8-character prefix (stored in cleartext alongside the ciphertext) and a fixed 142-byte suffix hardcoded within the application binaries. Because the key material is static across all installations and the unique prefix is provided in the output, an attacker with local access to the encrypted string can perform an offline decryption using a single SHA-1 and RC4 operation. No brute force is required to recover the plaintext password. The vendor has indicated the product is no longer maintained, so no patch is expected.
Affected products
- Lansweeper lsrunase 2.0
- Lansweeper lsencrypt 2.0
Timeline
- 2026-03-13: disclosed: Vendor notified via security@lansweeper.com
- 2026-03-31: other: Vendor responded that the product is no longer maintained
- 2026-06-08: other: CVE-2026-39031 assigned by MITRE
- 2026-06-26: advisory: Public disclosure and NVD publication