Junglewise Threat Intelligence

CVE-2026-39929: Lakeside SysTrack Agent out-of-bounds read in UDP handler

CVE-2026-39929 · Severity: high · CVSS 7.5 · Published 2026-05-28

Executive brief

Lakeside SysTrack Agent, a tool used for monitoring IT infrastructure and endpoint performance, is vulnerable to a remote attack that can crash the software. By sending a specifically malformed network packet, an attacker can cause the agent to stop functioning, leading to a denial of service. This disrupts the ability of IT teams to monitor and manage affected systems until the service is restored.

Technical details

An out-of-bounds read vulnerability exists in the Command ID 30 UDP packet handler within the LsiAgent.exe component of Lakeside SysTrack Agent. The flaw is triggered when the application processes a malformed UDP packet containing an invalid memory address at offset 0x4 in the payload. A remote, unauthenticated attacker can exploit this by sending a crafted packet to the agent's loopback or network-facing component, resulting in an access violation and application crash (Denial of Service). Patches are available in versions 11.2.1.28, 11.3.0.38, 11.4.0.24, and 11.5.0.15.

Affected products

  • Lakeside Software SysTrack Agent prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15

Timeline

  • 2026-01-05: patched: Hotfix releases published by vendor
  • 2026-05-28: disclosed: CVE published to NVD

References