LANSCOPE Endpoint Manager Flaw Allows Remote Code Execution
A critical security vulnerability has been identified in the on-premise edition of LANSCOPE Endpoint Manager. This flaw could potentially allow attackers to execute malicious code on affected machines.
A critical security vulnerability has been identified in the on-premise edition of LANSCOPE Endpoint Manager. This flaw could potentially allow attackers to execute malicious code on affected machines.
The vulnerability, designated as CVE-2025-61932 , is a remote code execution issue affecting two primary components: the Client Program (MR) and the Detection Agent (DA).
Instances of exploitation have been observed in the field, highlighting the urgency for users to apply the latest security patch.
Researchers have discovered that specially crafted network packets targeting systems with the affected versions can trigger a critical error. This error permits attackers to execute arbitrary commands with elevated privileges on the compromised system. Affected versions include 9.4.7.1 and earlier of both the MR client program and the DA detection agent.
A critical security vulnerability has been identified in the on-premise edition of LANSCOPE Endpoint Manager.
The vulnerability does not require user interaction, posing a significant risk as systems can be compromised without any user action.
Organizations utilizing the on-premise edition of Endpoint Manager are at urgent risk, whereas users of the Cloud Edition are not affected.
This vulnerability has been assigned a CVSS 3.0 score of 9.8, categorizing it as an "emergency" due to its severe potential impact and ease of exploitation. Below is a summary of the affected components:
CVE ID: CVE-2025-61932 Product: LANSCOPE Endpoint Manager On-Premise Edition CVSS 3.0 Score: 9.8
A security update is now available through the official LANSCOPE support portal. The vulnerability affects client-side software, necessitating updates on each client PC running the on-premise edition. The update for the Client Program (MR) and the Detection Agent (DA) follows the standard patch procedure of a regular software upgrade, with no requirement to update the manager console.
Based on reporting by GBHackers.
