📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Information Technology and Infrastructure HIGH 1h Global data_breach Education HIGH 1h Global data_breach Education HIGH 2h Global vulnerability Information Technology CRITICAL 2h Global supply_chain Software Development and Technology HIGH 3h Global vulnerability Information Technology and Telecommunications CRITICAL 3h Global apt Financial Services, Banking HIGH 9h Global vulnerability Technology and Software Development HIGH 12h Global vulnerability Government and Federal Agencies CRITICAL 12h Global supply_chain Software Development and Open-Source Ecosystems HIGH 13h Global vulnerability Information Technology and Infrastructure HIGH 1h Global data_breach Education HIGH 1h Global data_breach Education HIGH 2h Global vulnerability Information Technology CRITICAL 2h Global supply_chain Software Development and Technology HIGH 3h Global vulnerability Information Technology and Telecommunications CRITICAL 3h Global apt Financial Services, Banking HIGH 9h Global vulnerability Technology and Software Development HIGH 12h Global vulnerability Government and Federal Agencies CRITICAL 12h Global supply_chain Software Development and Open-Source Ecosystems HIGH 13h Global vulnerability Information Technology and Infrastructure HIGH 1h Global data_breach Education HIGH 1h Global data_breach Education HIGH 2h Global vulnerability Information Technology CRITICAL 2h Global supply_chain Software Development and Technology HIGH 3h Global vulnerability Information Technology and Telecommunications CRITICAL 3h Global apt Financial Services, Banking HIGH 9h Global vulnerability Technology and Software Development HIGH 12h Global vulnerability Government and Federal Agencies CRITICAL 12h Global supply_chain Software Development and Open-Source Ecosystems HIGH 13h
Vulnerabilities

CVE-2018-25232

Medium
Softros LAN Messenger 9.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the custom log files location field
CWE-1285 — Weakness Type
Published: Mar 30, 2026  ·  Modified: Apr 2, 2026  ·  Source: NVD
CVSS v3
5.5
🔗 NVD Official
📄 Description (English)

Softros LAN Messenger 9.2 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an excessively long string to the custom log files location field. Attackers can input a buffer of 2000 characters in the Log Files Location custom path parameter to trigger a crash when the OK button is clicked.

🤖 AI Executive Summary

Softros LAN Messenger 9.2 contains a denial of service vulnerability allowing local attackers to crash the application through buffer overflow in the log files location field. An attacker can input a 2000-character string to trigger application crash when configuration is saved. While CVSS is medium (5.5), the lack of available patches and local attack vector pose operational risks to organizations using this legacy communication tool.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 25, 2026 03:01
🇸🇦 Saudi Arabia Impact Assessment
Organizations in Saudi Arabia using Softros LAN Messenger 9.2 for internal communications face operational disruption risks. Most vulnerable sectors include: Government agencies and ministries relying on legacy communication tools, Banking sector back-office operations, Healthcare facilities using older messaging systems, and Telecom companies (STC, Mobily) with legacy infrastructure. The vulnerability enables local denial of service attacks, potentially disrupting internal communications and collaboration. Given the prevalence of legacy systems in Saudi government and critical infrastructure, this poses moderate operational risk despite medium CVSS score.
🏢 Affected Saudi Sectors
Government Banking Healthcare Telecommunications Energy
⚖️ Saudi Risk Score (AI)
5.2
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Inventory all systems running Softros LAN Messenger 9.2 across the organization
2. Restrict local access to the application settings/configuration interface through file permissions and access controls
3. Implement application whitelisting to prevent unauthorized execution
4. Monitor for unexpected application crashes and log file location configuration changes

Compensating Controls (No Patch Available):
1. Disable or restrict access to the Log Files Location configuration field through group policies or application hardening
2. Implement input validation at the OS level to limit string length in configuration files
3. Use application sandboxing or containerization to isolate the application
4. Enforce principle of least privilege for user accounts accessing this application
5. Consider migrating to modern, actively maintained communication platforms (Microsoft Teams, Slack, or approved enterprise solutions)

Detection Rules:
1. Monitor for Softros LAN Messenger process crashes in event logs
2. Alert on configuration file modifications with unusually long path strings
3. Track failed application startup attempts following configuration changes
4. Monitor registry/config file access patterns for suspicious modifications
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. حصر جميع الأنظمة التي تقوم بتشغيل Softros LAN Messenger 9.2 عبر المنظمة
2. تقييد الوصول المحلي إلى واجهة إعدادات التطبيق من خلال أذونات الملفات والتحكم في الوصول
3. تنفيذ قائمة بيضاء للتطبيقات لمنع التنفيذ غير المصرح به
4. مراقبة انهيارات التطبيق غير المتوقعة والتغييرات في إعدادات موقع ملف السجل

الضوابط التعويضية (لا يوجد تصحيح متاح):
1. تعطيل أو تقييد الوصول إلى حقل إعدادات موقع ملفات السجل من خلال سياسات المجموعة أو تقسية التطبيق
2. تنفيذ التحقق من صحة الإدخال على مستوى نظام التشغيل لتحديد طول السلسلة في ملفات الإعدادات
3. استخدام عزل التطبيقات أو الحاويات لعزل التطبيق
4. فرض مبدأ أقل امتياز لحسابات المستخدمين التي تصل إلى هذا التطبيق
5. النظر في الترقية إلى منصات اتصالات حديثة وتحت الصيانة النشطة (Microsoft Teams أو Slack أو الحلول المعتمدة)

قواعد الكشف:
1. مراقبة انهيارات عملية Softros LAN Messenger في سجلات الأحداث
2. التنبيه على تعديلات ملفات الإعدادات بسلاسل مسار طويلة بشكل غير عادي
3. تتبع محاولات بدء التطبيق الفاشلة بعد التغييرات في الإعدادات
4. مراقبة أنماط الوصول إلى ملفات السجل/الإعدادات للتعديلات المريبة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.5.1.1 - Information Security Policies (legacy system management) A.8.1.1 - User Access Management (restrict configuration access) A.12.2.1 - Change Management (monitor configuration changes) A.12.6.1 - Management of Technical Vulnerabilities (legacy system inventory)
🔵 SAMA CSF
ID.AM-2 - Asset Management (inventory legacy systems) PR.AC-1 - Access Control Policy (restrict local access) PR.IP-1 - Security Policy and Process (legacy system management) DE.CM-1 - System Monitoring (detect application crashes)
🟡 ISO 27001:2022
A.5.1 - Management Direction (legacy system governance) A.8.1 - User Access Management (principle of least privilege) A.12.2 - Change Management (configuration change control) A.12.6 - Management of Technical Vulnerabilities (vulnerability assessment)
📊 CVSS Score
5.5
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Attack VectorL — Low / Local
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionR — Required
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityN — None / Network
AvailabilityH — High
📋 Quick Facts
Severity Medium
CVSS Score5.5
CWECWE-1285
EPSS0.01%
Exploit No
Patch ✗ No
Published 2026-03-30
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
5.2
/ 10.0 — Saudi Risk
Priority: MEDIUM
🏷️ Tags
CWE-1285
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.