PT-2020-11886 · Unknown · License Management Utility
Published
2020-09-09
·
Updated
2023-01-24
·
CVE-2020-10056
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
License Management Utility (LMU) versions prior to V2.4
Description
A security issue has been identified where the lmgrd service of the affected application runs with local SYSTEM privileges on the server, and its configuration can be modified by local users. This could allow a local authenticated attacker to execute arbitrary commands on the server with local SYSTEM privileges.
Recommendations
For versions prior to V2.4, update to version V2.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the lmgrd service configuration to prevent local users from modifying it.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
License Management Utility