CVE-2025-34165Disclosure

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (4 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A stack-based buffer overflow vulnerability in NetSupport Manager 14.x versions prior to 14.12.0000 allows a remote, unauthenticated attacker to cause a denial of service (DoS) or potentially leak a limited amount of memory.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-121

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-02-09)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-08: 1Mentions · 2026-02-09: 4PoC Mentioned / Linked · 2026-02-08: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 402-0802-09
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-081
Disclosure1
2026-02-094
Disclosure3General1
Full discourse5 posts
  • 0xor0ne@0xor0ne
    Disclosure

    Unauthenticated RCE in NetSupport Manager by chaining CVE-2025-34164 (heap OOB write) and CVE-2025-34165 (stack OOB read) https://code-white.com/blog/2026-01-nsm-rce/ Credits Fabian Weber (@codewhitesec) #infosec https://t.co/qkOEJerH4e

    Post summary

    The post discloses an unauthenticated RCE in NetSupport Manager by chaining CVE‑2025‑34164 (heap OOB write) and CVE‑2025‑34165 (stack OOB read), providing technical details but no evidence of active exploitation or patch status.

    3340125467.7K
    87.7K followersView on X
  • transilienceai@transilienceai
    Disclosure

    @0xor0ne @tensxu @codewhitesec CVE-2025-34164 and CVE-2025-34165 are two vulnerabilities in NetSupport Manager (versions 14.x prior to 14.12.0000) that enable unauthenticated remote code execution (RCE) when chained together. #CyberSecurity #Vulnerabilities

    Post summary

    The post announces two CVEs (CVE‑2025‑34164 & CVE‑2025‑34165) that allow unauthenticated RCE in NetSupport Manager when chained, but does not provide PoC, exploit code, patch, or evidence of active exploitation.

    1101085
    315 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @0xor0ne @Opensourcedtech @codewhitesec CVE-2025-34164 and CVE-2025-34165 are two vulnerabilities in NetSupport Manager (versions 14.x prior to 14.12.0000) that enable unauthenticated remote code execution (RCE) when chained together. ⚠️💻 #CyberSecurity #Vulnerability

    Post summary

    The tweet discloses that CVE-2025-34164 and CVE-2025-34165 in NetSupport Manager allow unauthenticated remote code execution when chained together.

    1101087
    315 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @0xor0ne @tensxu @codewhitesec The stack OOB read (CVE-2025-34165) occurs due to missing size checks on the *BC_TCP_DATA* command, allowing data sizes exceeding the 0x800-byte aggregate buffer limit. This enables reading uninitialized stack memory. #BufferOverflow #CyberThreat

    Post summary

    The tweet discloses an out‑of‑bounds read vulnerability (CVE‑2025‑34165) caused by missing size checks in the *BC_TCP_DATA* command, allowing reads beyond a 0x800‑byte buffer and exposing uninitialized stack memory.

    1000052
    315 followersView on X
  • transilienceai@transilienceai
    General

    @0xor0ne @qbao0808 @codewhitesec 1. Use CVE-2025-34165 to send oversized BC_TCP_DATA with a valid PING command, enabling stack OOB read for info leaks or control.

    Post summary

    The tweet explains an exploitation technique for CVE-2025-34165 involving an oversized BC_TCP_DATA and a valid PING command to trigger a stack out‑of‑bounds read, but it does not provide a PoC, patch, or evidence of active use.

    1000047
    315 followersView on X

Explore more