Vulnerability record · CVE-2007-1674 · published 18 April 2007
CVE-2007-1674: LANDesk Management Suite Alert Service UDP buffer overflow
Landesk · Landesk Management Suite
The Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 contains a stack-based buffer overflow reachable via a crafted packet sent to UDP port 65535. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary code on the host running the service. The record covers only version 8.7, so other versions cannot be confirmed as affected from this data.
Description
Stack-based buffer overflow in the Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 allows remote attackers to execute arbitrary code via a crafted packet to port 65535/UDP.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score of 10 with a network-reachable, unauthenticated buffer overflow that yields full code execution, plus very high EPSS and public exploit references, makes this a top remediation priority despite the absence of KEV listing.
What it is
The Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 contains a stack-based buffer overflow reachable via a crafted packet sent to UDP port 65535. A remote, unauthenticated attacker can trigger the overflow and execute arbitrary code on the host running the service. The record covers only version 8.7, so other versions cannot be confirmed as affected from this data.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the Alert Service process, which typically runs as a system-level service on managed endpoints and servers. That level of access can lead to full compromise of the host and any credentials or management data it holds.
Attack surface
The flaw is network-reachable: a single crafted UDP packet to port 65535 is sufficient, with no authentication and no user interaction required per the CVSS vector (AV:N/AC:L/Au:N). Any host that can route UDP traffic to the exposed port can attempt the attack.
Exploitation
The record is not listed in CISA KEV and no ransomware use is documented, but EPSS is very high (0.72864, 99.4th percentile) and multiple references are tagged Exploit, indicating public exploit material exists. No confirmed in-the-wild activity is stated in this record.
What to do
- Apply the vendor patch referenced in the LANDesk knowledge base article and TippingPoint advisory, and upgrade LANDesk Management Suite 8.7 to a fixed release.
- Block or restrict inbound UDP port 65535 to the Alert Service so only trusted management hosts can reach it, using host and network firewalls.
- Segment management servers and managed endpoints so the Alert Service is not exposed to untrusted networks.
- If the Alert Service is not required, disable it; otherwise run it with the least privilege possible rather than a system-level account.
- Monitor vendor advisories for updated guidance, since this is an old record and only version 8.7 is documented.
Detection
- Alert on any inbound UDP traffic to port 65535 from hosts outside the expected management subnet.
- Monitor aolnsrvr.exe for crashes, restarts or unexpected child processes, which can indicate a failed or successful overflow attempt.
- Hunt for anomalous process creation or network connections originating from the Alert Service process on LANDesk hosts.
- Review firewall and IDS/IPS logs for repeated or malformed UDP packets targeting port 65535.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-1674 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-1674), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.