Vulnerability record · CVE-2011-0404 · published 11 January 2011
CVE-2011-0404: NetSupport Manager Agent stack buffer overflow via control hostname
Netsupport · Netsupport Manager Agent
A stack-based buffer overflow exists in the NetSupport Manager Agent for Linux 11.00, Solaris 9.50, and Mac OS X 11.00 when handling a long control hostname sent to TCP port 5405. A remote, unauthenticated attacker can trigger the overflow and potentially execute arbitrary code on the affected host.
Description
Stack-based buffer overflow in NetSupport Manager Agent for Linux 11.00, for Solaris 9.50, and for Mac OS X 11.00 allows remote attackers to execute arbitrary code via a long control hostname to TCP port 5405, probably a different vulnerability than CVE-2007-5252.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution with public exploit code and very high EPSS probability, though not listed in CISA KEV.
What it is
A stack-based buffer overflow exists in the NetSupport Manager Agent for Linux 11.00, Solaris 9.50, and Mac OS X 11.00 when handling a long control hostname sent to TCP port 5405. A remote, unauthenticated attacker can trigger the overflow and potentially execute arbitrary code on the affected host.
Impact
Successful exploitation allows remote code execution with the privileges of the NetSupport Manager Agent process, giving an attacker control of the affected endpoint. The CVSS 2.0 vector indicates partial confidentiality, integrity, and availability impact.
Attack surface
The flaw is reachable over the network via TCP port 5405, the agent's control channel. The CVSS vector (AV:N/AC:L/Au:N) indicates no authentication is required and no user interaction is needed.
Exploitation
Public exploit code is referenced (Exploit-DB 15937 and 16838, Ikkisoft advisory, SecurityFocus BID 45728), and EPSS is 0.64739 (99.2nd percentile), indicating a high likelihood of exploitation activity. The CVE is not listed in CISA KEV.
What to do
- Apply the vendor patch or upgrade NetSupport Manager Agent to a fixed version as soon as possible.
- Restrict network access to TCP port 5405 to trusted management hosts only, using firewall or ACL rules.
- Disable or uninstall the NetSupport Manager Agent on systems that do not require remote management.
- Monitor vendor advisories for updated guidance and confirm the fixed version covers Linux, Solaris, and Mac OS X agents.
- Segment management traffic so agent control channels are not exposed to untrusted networks.
Detection
- Monitor network traffic to TCP port 5405 for unusually long hostname fields or malformed control messages.
- Inspect host logs and process behavior for crashes or unexpected child processes spawned by the NetSupport Manager Agent.
- Use IDS/IPS signatures that detect oversized control hostname payloads targeting port 5405.
- Audit exposed instances of NetSupport Manager Agent on Linux, Solaris, and Mac OS X hosts and verify patch status.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-0404 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-0404), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.