← Vulnerability feed

Vulnerability record · CVE-2005-1543 · published 25 May 2005

CVE-2005-1543: Novell ZENworks Remote Management authentication buffer overflows

Novell · Zenworks

The Remote Management authentication component (zenrem32.exe) in Novell ZENworks Desktop and Server Management contains multiple stack-based and heap-based buffer overflows. They are reachable through unspecified vectors and through type 1 and type 2 authentication requests, allowing remote code execution. The flaw matters because the affected service is network-facing and the overflows can be triggered without credentials.

7.5 CVSS 2.0 High EPSS 66% · top 0.7%
7.5CVSS 2.0 base score
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based and heap-based buffer overflows in Remote Management authentication (zenrem32.exe) on Novell ZENworks 6.5 Desktop and Server Management, ZENworks for Desktops 4.x, ZENworks for Servers 3.x, and Remote Management allows remote attackers to execute arbitrary code via (1) unspecified vectors, (2) type 1 authentication requests, and (3) type 2 authentication requests.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityNetwork-reachable, unauthenticated buffer overflows with a very high EPSS score, though no KEV listing or confirmed exploit code is present in the record.

What it is

The Remote Management authentication component (zenrem32.exe) in Novell ZENworks Desktop and Server Management contains multiple stack-based and heap-based buffer overflows. They are reachable through unspecified vectors and through type 1 and type 2 authentication requests, allowing remote code execution. The flaw matters because the affected service is network-facing and the overflows can be triggered without credentials.

Impact

A remote attacker can execute arbitrary code in the context of the vulnerable ZENworks Remote Management service. That can lead to full compromise of the host running the service.

Attack surface

The vulnerability is reached over the network via the Remote Management authentication path (zenrem32.exe), including crafted type 1 and type 2 authentication requests. The CVSS vector AV:N/AC:L/Au:N indicates no authentication is required and no user interaction is needed.

Exploitation

CVE-2005-1543 is not listed in CISA KEV, but EPSS is very high (0.66102, 99.2nd percentile), indicating a strong likelihood of exploitation activity. No public exploit code or in-the-wild campaign is confirmed by the supplied references.

What to do

  • Apply the Novell vendor fix referenced in the Novell support document and vendor advisory; treat patching as the first action.
  • If the Remote Management authentication service is not required, disable or uninstall it on ZENworks 6.5, ZENworks for Desktops 4.x, and ZENworks for Servers 3.x hosts.
  • Restrict network access to the Remote Management authentication port to trusted management subnets only.
  • Segment or isolate ZENworks management servers so a compromised service cannot reach broader enterprise systems.
  • Monitor vendor channels for updated guidance, since the supplied record does not list fixed version numbers.

Detection

  • Monitor for crashes or abnormal termination of zenrem32.exe on ZENworks hosts.
  • Inspect network traffic to the Remote Management authentication service for malformed or oversized authentication requests, especially type 1 and type 2 requests.
  • Alert on unexpected child processes or command execution spawned by the ZENworks Remote Management service.
  • Review host logs for repeated authentication attempts against the Remote Management service from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-1543 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2005-1543), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.