Description
LanSpy 2.0.1.159 contains a local buffer overflow vulnerability in the scan section that allows local attackers to execute arbitrary code by exploiting structured exception handling mechanisms. Attackers can craft malicious payloads using egghunter techniques to locate and execute shellcode, triggering code execution through SEH chain manipulation and controlled jumps.
References
Product
https://www.exploit-db.com/exploits/46018
ExploitVDB Entry
https://www.vulncheck.com/advisories/lanspy-local-buffer-overflow
Third Party Advisory
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
8.4 · High
Information
Source identifier
Vulnerability status
Analyzed
Published
2026-04-22T16:16:46.907Z
5 months agoLast modified
2026-06-17T01:55:07.023Z
3 months ago