PT-2017-2426 · Revenera · Flexnet Publisher
Published
2017-06-15
·
Updated
2018-05-30
·
CVE-2016-10395
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
FlexNet Publisher versions before 11.14.1.1 (Luton SP1)
Description
The issue is caused by a boundary error related to a named pipe within the FlexNet Publisher Licensing Service, which can be exploited to cause an out-of-bounds memory read access and subsequently execute arbitrary code with SYSTEM privileges. This can allow a remote attacker to execute arbitrary code with system privileges.
Recommendations
For versions before 11.14.1.1 (Luton SP1), update to Luton SP1 (11.14.1.1) or later to resolve the issue. As a temporary workaround, consider restricting access to the FlexNet Publisher Licensing Service to minimize the risk of exploitation.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flexnet Publisher