CVE-2025-34164Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (5 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A heap-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or execute arbitrary code.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 4 classified signals
  • Peaked at 5 mentions on most recent observed day (2026-02-09)
  • 7 total mentions across 3 days

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-01-27: 1Mentions · 2026-02-08: 1Mentions · 2026-02-09: 5PoC Mentioned / Linked · 2026-01-27: 1PoC Mentioned / Linked · 2026-02-08: 1Patch / Workaround · 2026-01-27: 1Technical Details · 2026-01-27: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 501-2702-0802-09
Signal classification4 categories
Disclosure
457.1%
Patch
114.3%
PoC
114.3%
General
114.3%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-01-271
Patch1
2026-02-081
PoC1
2026-02-095
Disclosure4General1
Full discourse7 posts
  • 0xor0ne@0xor0ne
    PoC

    Unauthenticated RCE in NetSupport Manager by chaining CVE-2025-34164 (heap OOB write) and CVE-2025-34165 (stack OOB read) https://code-white.com/blog/2026-01-nsm-rce/ Credits Fabian Weber (@codewhitesec) #infosec https://t.co/qkOEJerH4e

    Post summary

    The tweet announces an unauthenticated remote code execution in NetSupport Manager via chained CVE-2025-34164 and CVE-2025-34165, with a link to a blog that likely contains proof‑of‑concept details.

    3340125467.7K
    87.7K followersView on X
  • transilienceai@transilienceai
    Disclosure

    @0xor0ne @tensxu @codewhitesec CVE-2025-34164 and CVE-2025-34165 are two vulnerabilities in NetSupport Manager (versions 14.x prior to 14.12.0000) that enable unauthenticated remote code execution (RCE) when chained together. #CyberSecurity #Vulnerabilities

    Post summary

    The post announces two NetSupport Manager vulnerabilities (CVE‑2025‑34164 and CVE‑2025‑34165) that allow unauthenticated remote code execution when chained together.

    1101085
    315 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @0xor0ne @Opensourcedtech @codewhitesec CVE-2025-34164 and CVE-2025-34165 are two vulnerabilities in NetSupport Manager (versions 14.x prior to 14.12.0000) that enable unauthenticated remote code execution (RCE) when chained together. ⚠️💻 #CyberSecurity #Vulnerability

    Post summary

    The post announces two CVEs (CVE-2025-34164 and CVE-2025-34165) that allow unauthenticated remote code execution in NetSupport Manager 14.x versions prior to 14.12.0000 when the vulnerabilities are chained together.

    1101087
    315 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @0xor0ne @tensxu @codewhitesec CVE-2025-34164 (Heap-based buffer overflow) allows a remote, unauthenticated attacker to cause a denial of service (DoS) or execute arbitrary code via a heap out-of-bounds (OOB) write. It has a CVSS score of 9.3 and was published on August 29, 2025. #RCE #Security

    Post summary

    The tweet announces CVE-2025-34164, a heap-based buffer overflow that allows remote code execution or DoS, but provides no PoC, exploit, or patch details.

    1000049
    315 followersView on X
  • transilienceai@transilienceai
    General

    @0xor0ne @qbao0808 @codewhitesec 2. Leverage CVE-2025-34164's heap OOB write to craft fake structures (e.g., vtable pointers, udp_data_control, SendWindow instances) at controlled addresses.

    Post summary

    The tweet references CVE-2025-34164, highlighting a heap OOB write that could be used to forge structures, but it provides no PoC, patch, or evidence of active exploitation.

    1000034
    315 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @0xor0ne @Opensourcedtech @codewhitesec Researchers at Code White discovered these as zero-days and combined them for unauthenticated RCE: 🔗 The heap OOB write (CVE-2025-34164) corrupts memory, such as overwriting vtable pointers. #ZeroDay

    Post summary

    Researchers identified a zero‑day heap OOB write (CVE‑2025‑34164) that can be exploited for unauthenticated RCE by corrupting memory, but no patch or PoC details are provided.

    1000046
    315 followersView on X
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2025-34164 : CRITICAL PRE-AUTH RCE ALERT 🚨 @NetSupportGroup   A pre-authentication remote code execution vulnerability has been disclosed in NetSupport Manager, a widely deployed enterprise remote administration platform used across corporate, education, and government environments. Risk Severity: Critical (unauthenticated RCE, trending, public PoC available) Impact: • Pre-auth remote code execution • SYSTEM-level compromise on Windows servers • Full takeover of NetSupport management servers • Ransomware deployment at scale • Lateral movement to all managed endpoints Root Cause: CWE-122 (Heap-Based Buffer Overflow). NetSupport Manager fails to enforce proper bounds checking when processing network packets before authentication, allowing attackers to overflow heap buffers and hijack execution flow. Attackers can: • Exploit exposed NetSupport services without credentials • Execute arbitrary code as NT AUTHORITY\SYSTEM • Disable security controls or deploy malware • Abuse legitimate management features to pivot laterally • Crash services to cause denial of service Are You Affected? Vulnerable: NetSupport Manager 14.x < 14.12.0000 Scope: Management servers reachable from internal or untrusted networks Immediate Action Required: Update: Upgrade to NetSupport Manager 14.12.0000+ immediately Mitigation: Restrict TCP 5421/5422 to management VLANs; remove internet exposure Audit: Hunt for nsservice.exe crashes and unexpected child processes Remote management platforms are Tier-0 ransomware targets. Patch now. 🛡️ #netsupport #security #ostorlabCVE

    Post summary

    A critical pre‑authentication RCE (CVE‑2025‑34164) in NetSupport Manager is disclosed with a public PoC; immediate patching to version 14.12.0000+ and network restrictions are recommended to prevent system compromise and potential ransomware deployment.

    0000099
    582 followersView on X

Explore more