0xor0ne[verified]@0xor0neDisclosure
The post discloses an unauthenticated RCE in NetSupport Manager by chaining CVE‑2025‑34164 (heap OOB write) and CVE‑2025‑34165 (stack OOB read), providing technical details but no evidence of active exploitation or patch status.
transilienceai[verified]@transilienceaiDisclosure
The post announces two CVEs (CVE‑2025‑34164 & CVE‑2025‑34165) that allow unauthenticated RCE in NetSupport Manager when chained, but does not provide PoC, exploit code, patch, or evidence of active exploitation.
transilienceai[verified]@transilienceaiDisclosure
The tweet discloses that CVE-2025-34164 and CVE-2025-34165 in NetSupport Manager allow unauthenticated remote code execution when chained together.
transilienceai[verified]@transilienceaiDisclosure
The tweet discloses an out‑of‑bounds read vulnerability (CVE‑2025‑34165) caused by missing size checks in the *BC_TCP_DATA* command, allowing reads beyond a 0x800‑byte buffer and exposing uninitialized stack memory.
transilienceai[verified]@transilienceaiGeneral
The tweet explains an exploitation technique for CVE-2025-34165 involving an oversized BC_TCP_DATA and a valid PING command to trigger a stack out‑of‑bounds read, but it does not provide a PoC, patch, or evidence of active use.