Executive brief
Lakeside SysTrack Agent, a tool used for monitoring IT infrastructure and endpoint performance, is vulnerable to a remote attack that can crash the software. By sending a specifically malformed network packet, an attacker can cause the agent to stop functioning, leading to a denial of service. This disrupts the ability of IT teams to monitor and manage affected systems until the service is restored.
Technical details
An out-of-bounds read vulnerability exists in the Command ID 30 UDP packet handler within the LsiAgent.exe component of Lakeside SysTrack Agent. The flaw is triggered when the application processes a malformed UDP packet containing an invalid memory address at offset 0x4 in the payload. A remote, unauthenticated attacker can exploit this by sending a crafted packet to the agent's loopback or network-facing component, resulting in an access violation and application crash (Denial of Service). Patches are available in versions 11.2.1.28, 11.3.0.38, 11.4.0.24, and 11.5.0.15.
Affected products
- Lakeside Software SysTrack Agent prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15
Timeline
- 2026-01-05: patched: Hotfix releases published by vendor
- 2026-05-28: disclosed: CVE published to NVD
References
- https://documentation.lakesidesoftware.com/docs/112128-hotfix-agent-release-notes
- https://documentation.lakesidesoftware.com/docs/1130xxx-hotfix-agent-release-notes
- https://documentation.lakesidesoftware.com/docs/1140xxx-hotfix-agent-release-notes
- https://documentation.lakesidesoftware.com/docs/1150xxx-hotfix-agent-release-notes
- https://www.vulncheck.com/advisories/lakeside-systrack-agent-lsiagent-exe-out-of-bounds-read-via-udp