


Perceptive Security
SOC/SIEM Consultancy

LanSpy 2.0.1.159 contains a local buffer overflow vulnerability in the scan section that allows local attackers to execute arbitrary code by exploiting structur…
Published:
21 april 2026 om 22:00:00
Alert date:
22 april 2026 om 22:11:22
Source:
nvd.nist.gov
Network Infrastructure, Security Tools
CVE-2018-25265 affects LanSpy version 2.0.1.159, a network scanning tool. The vulnerability is a local buffer overflow in the scan section that allows attackers to execute arbitrary code. Exploitation involves structured exception handling (SEH) mechanisms and egghunter techniques to locate and execute shellcode. Attackers can manipulate the SEH chain and perform controlled jumps to achieve code execution. This requires local access to the system running the vulnerable LanSpy application.
Technical details
Mitigation steps:
Affected products:
LanSpy
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2018-25265
https://lizardsystems.com
https://www.exploit-db.com/exploits/46018
https://www.vulncheck.com/advisories/lanspy-local-buffer-overflow
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
