vulnti.work

Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers t…

High CVSS 7.5
CVECVE-2026-39929
First seen2026-07-21 11:15 UTC
Disclosed2026-05-28 22:16 UTC
Last updated2026-07-21 11:15 UTC
Channel statusauto

Summary

Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers to crash the application by sending a specially crafted UDP packet. Attackers can send a malformed packet with an invalid memory address at offset 0x4 in the payload to trigger an access violation and cause a denial of service.

In-depth triage · Auto channel

No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).

Lint boundary warnings (4)

The following non-blocking warnings were raised during the lint phase of this triage (e.g. reference URLs not yet on the allowlist). They do not affect entry usability and are disclosed for transparency (see DR-002).

  • REF_URL_NOT_ALLOWLISTED url not in allowlist: https://documentation.lakesidesoftware.com/docs/112128-hotfix-agent-release-notes
  • REF_URL_NOT_ALLOWLISTED url not in allowlist: https://documentation.lakesidesoftware.com/docs/1130xxx-hotfix-agent-release-notes
  • REF_URL_NOT_ALLOWLISTED url not in allowlist: https://documentation.lakesidesoftware.com/docs/1140xxx-hotfix-agent-release-notes
  • REF_URL_NOT_ALLOWLISTED url not in allowlist: https://documentation.lakesidesoftware.com/docs/1150xxx-hotfix-agent-release-notes

Sources

  • NVD DATABASE

Original Links

Timeline

  1. nvd_ingest NVD