8.7
/ 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Description
Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers to crash the application by sending a specially crafted UDP packet. Attackers can send a malformed packet with an invalid memory address at offset 0x4 in the payload to trigger an access violation and cause a denial of service.
AI Analysis
Out-of-bounds read vulnerability in Lakeside SysTrack Agent via UDP packet handler
Basic Information
ID
CVE-2026-39929
Source
VulnCheck
Published
May 28, 2026 at 21:14
Affected Product
Vendor
Lakeside Software, LLC.
Product
SysTrack Agent
Affected Versions
Lakeside Software, LLC. SysTrack Agent 0
Lakeside Software, LLC. SysTrack Agent 11.3.0.xxx
Lakeside Software, LLC. SysTrack Agent 11.4.0.xxx
Lakeside Software, LLC. SysTrack Agent 11.5.0.xxx
Lakeside Software, LLC. SysTrack Agent 11.3.0.xxx
Lakeside Software, LLC. SysTrack Agent 11.4.0.xxx
Lakeside Software, LLC. SysTrack Agent 11.5.0.xxx
CWE Classification
AI Assessment
AI Score
8.7 / 10
AI Severity
High
Vendor
Lakeside Software, LLC.
Product
SysTrack Agent
Version
< 11.2.1.28, < 11.3.0.38, < 11.4.0.24, < 11.5.0.15
References
- documentation.lakesidesoftware.com /docs/112128-hotfix-agent-release-notes
- documentation.lakesidesoftware.com /docs/1130xxx-hotfix-agent-release-notes
- documentation.lakesidesoftware.com /docs/1140xxx-hotfix-agent-release-notes
- documentation.lakesidesoftware.com /docs/1150xxx-hotfix-agent-release-notes
- www.vulncheck.com /advisories/lakeside-systrack-agent-lsiagent-exe-out-of-bounds-read-via-udp