CVE-2025-34181

NetSupport ManagerĀ < 14.12.0001 contains an arbitrary file write vulnerability in its Connectivity Server/Gateway PUTFILE request handler. An attacker with a valid Gateway Key can supply a crafted filename containing directory traversal sequences to write files to arbitrary locations on the server. This can be leveraged to place attacker-controlled DLLs or executables in privileged paths and achieve remote code execution in the context of the NetSupport Manager connectivity service.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2025-12-15 15:15

Updated : 2025-12-15 19:16


NVD link : CVE-2025-34181

Mitre link : CVE-2025-34181

CVE.ORG link : CVE-2025-34181


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')