CVE-2008-0764 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 7.4% (pctl 94)
Patch early
A public exploit exists.
Description
Format string vulnerability in the logging function in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier for Windows might allow remote attackers to execute arbitrary code via format string specifiers in a USEP command on TCP port 3114.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 7.4% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-134 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-02-13 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| larson software technology | network print server |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Larson Network Print Server 9.4.2 build 105 - 'LstNPS' Logging Function USEP Command Remote Format String | 2008-02-11 |
References
- http://aluigi.altervista.org/adv/lstnpsx-adv.txt
- http://secunia.com/advisories/28890
- http://www.securityfocus.com/archive/1/487956/100/0/threaded
- http://www.securityfocus.com/bid/27732
- http://www.vupen.com/english/advisories/2008/0500
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40420
- http://aluigi.altervista.org/adv/lstnpsx-adv.txt
- http://secunia.com/advisories/28890
- http://www.securityfocus.com/archive/1/487956/100/0/threaded
- http://www.securityfocus.com/bid/27732
- http://www.vupen.com/english/advisories/2008/0500
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40420
→ the Explorer · watch your stack · NVD