Vulnerability record · CVE-2008-5159 · published 18 November 2008
CVE-2008-5159: WinCom LPD Total remote admin protocol integer overflow
CClientsoftware · Wincome Mpd Total
WinCom LPD Total 3.0.2.623 and earlier mishandles a large string length argument in its remote administration protocol processing, causing an integer overflow that leads to memory corruption. The flaw is remotely reachable over the network without authentication, so any exposed LPD administration service is at risk.
Description
Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earlier allows remote attackers to cause a denial of service (crash) via a large string length argument, which triggers memory corruption.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityUnauthenticated remote memory corruption with a public proof of concept and very high EPSS, though impact is documented only as denial of service.
What it is
WinCom LPD Total 3.0.2.623 and earlier mishandles a large string length argument in its remote administration protocol processing, causing an integer overflow that leads to memory corruption. The flaw is remotely reachable over the network without authentication, so any exposed LPD administration service is at risk.
Impact
An attacker can crash the service, causing a denial of service. The CVSS vector claims full confidentiality, integrity and availability impact, but the description only demonstrates memory corruption and a crash, so code execution is not confirmed by the record.
Attack surface
Reached over the network via the remote administration protocol (AV:N, AC:L, Au:N). No authentication or user interaction is required per the vector and description.
Exploitation
Not listed in CISA KEV and no ransomware association. EPSS is high at roughly 0.597 (99th percentile), and public references include an advisory and a proof-of-concept archive, indicating exploit code is publicly available.
What to do
- Upgrade WinCom LPD Total past 3.0.2.623 or apply the vendor fix referenced in the Secunia advisory.
- Restrict network access to the remote administration protocol to trusted management hosts only.
- Block or firewall the administration port from untrusted networks and the internet.
- Monitor the vendor for an updated release if no fixed version is documented.
Detection
- Alert on LPD administration service crashes or unexpected process termination.
- Inspect network traffic to the admin protocol for oversized length fields or malformed strings.
- Correlate repeated connection attempts to the admin port from single sources with crash events.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-5159 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-5159), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.