NetSupport Manager < 14.12.0001 Authenticated Path Traversal Arbitrary File Write RCE
Vulnerability Description
NetSupport Manager < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacker with a valid Gateway Key can supply a crafted filename containing directory traversal sequences to write files to arbitrary locations on the server. This can be leveraged to place attacker-controlled DLLs or executables in privileged paths and achieve remote code execution in the context of the NetSupport Manager connectivity service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-34181
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Chris Leech
References
Affected Vendor
NetSupport Software
View all reports →