PT-2023-9837 · Unknown+1 · Flexnet Publisher+1
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FlexNet Publisher versions prior to 2024 R1 (11.19.6.0)
Description
A misconfiguration in the
lmadmin.exe executable allows the OpenSSL configuration file to be loaded from a non-existent directory. This issue, categorized as an Uncontrolled Search Path Element, occurs because the application references the OpenSSL configuration file using a hardcoded path without enforcing access restrictions. A locally authenticated user with low privileges can create the missing directory and place a specially crafted openssl.conf file within it. This can lead to the loading of a malicious DLL (Dynamic-Link Library) into the lmadmin.exe process, resulting in arbitrary code execution with elevated privileges, potentially reaching the NT AUTHORITYSYSTEM level. This flaw has been reported as actively exploited in the wild.Recommendations
Update FlexNet Publisher to version 2024 R1 (11.19.6.0) or later.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Flexnet Publisher
Openssl