
CVE-2024-2658 – Local privilege escalation in FlexNet Publisher
https://notcve.org/view.php?id=CVE-2024-2658
01 Apr 2024 — A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges. This vulnerability allows local attackers to escalate privileges on affected installations of Flexera... • https://community.flexera.com/s/article/cve-2024-2658-flexnet-publisher-potential-local-privilege-escalation-issue • CWE-427: Uncontrolled Search Path Element •

CVE-2019-8963
https://notcve.org/view.php?id=CVE-2019-8963
29 Mar 2023 — A Denial of Service (DoS) vulnerability was discovered in FlexNet Publisher's lmadmin 11.16.5, when doing a crafted POST request on lmadmin using the web-based tool. • https://community.flexera.com/t5/FlexNet-Publisher-Knowledge-Base/CVE-2019-8963-Remediated-in-FlexNet-Publisher/ta-p/148768 •

CVE-2020-12080
https://notcve.org/view.php?id=CVE-2020-12080
17 Sep 2021 — A Denial of Service vulnerability has been identified in FlexNet Publisher's lmadmin.exe version 11.16.6. A certain message protocol can be exploited to cause lmadmin to crash. Se ha identificado una vulnerabilidad de denegación de servicio en el archivo lmadmin.exe de FlexNet Publisher versión 11.16.6. Un determinado protocolo de mensajes puede ser explotado para causar un bloqueo de lmadmin • https://community.flexera.com/t5/FlexNet-Publisher-Knowledge-Base/CVE-2020-12080-Remediated-in-FlexNet-Publisher/ta-p/143873 • CWE-20: Improper Input Validation •

CVE-2020-12081
https://notcve.org/view.php?id=CVE-2020-12081
31 Jul 2020 — An information disclosure vulnerability has been identified in FlexNet Publisher lmadmin.exe 11.14.0.2. The web portal link can be used to access to system files or other important files on the system. Se ha identificado una vulnerabilidad de divulgación de información en FlexNet Publisher lmadmin.exe versión 11.14.0.2. El enlace del portal web puede ser usado para acceder a los archivos del sistema u otros archivos importantes en el sistema • https://community.flexera.com/t5/FlexNet-Publisher-Knowledge-Base/CVE-2020-12081-Remediated-in-FlexNet-Publisher/ta-p/153505 •

CVE-2019-8960
https://notcve.org/view.php?id=CVE-2019-8960
21 Apr 2020 — A Denial of Service vulnerability related to command handling has been identified in FlexNet Publisher lmadmin.exe version 11.16.2. The message reading function used in lmadmin.exe can, given a certain message, call itself again and then wait for a further message. With a particular flag set in the original message, but no second message received, the function eventually return an unexpected value which leads to an exception being thrown. The end result can be process termination. Se ha identificado una vul... • https://community.flexera.com/t5/FlexNet-Publisher-Knowledge-Base/CVE-2019-8960-remediated-in-FlexNet-Publisher/ta-p/124598/jump-to/first-unread-message • CWE-754: Improper Check for Unusual or Exceptional Conditions •

CVE-2019-8961
https://notcve.org/view.php?id=CVE-2019-8961
21 Apr 2020 — A Denial of Service vulnerability related to stack exhaustion has been identified in FlexNet Publisher lmadmin.exe 11.16.2. Because the message reading function calls itself recursively given a certain condition in the received message, an unauthenticated remote attacker can repeatedly send messages of that type to cause a stack exhaustion condition. Se ha identificado una vulnerabilidad de denegación de servicio relacionada con un agotamiento de pila (stack) en lmadmin.exe de FlexNet Publisher versión 11.1... • https://community.flexera.com/t5/FlexNet-Publisher-Knowledge-Base/CVE-2019-8961-remediated-in-FlexNet-Publisher/ta-p/124601/jump-to/first-unread-message • CWE-674: Uncontrolled Recursion •

CVE-2018-20034
https://notcve.org/view.php?id=CVE-2018-20034
21 Mar 2019 — A Denial of Service vulnerability related to adding an item to a list in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down. Una vulnerabilidad de denegación de servicio (DoS) relacionada con la adición de un ítem a una lista en los componentes del demonio lmgrd y del fabricante de Fl... • http://www.securityfocus.com/bid/109155 •

CVE-2018-20032
https://notcve.org/view.php?id=CVE-2018-20032
21 Mar 2019 — A Denial of Service vulnerability related to message decoding in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down. Una vulnerabilidad de denegación de servicio (DoS) relacionada con el descifrado de mensajes en los componentes del demonio lmgrd y del fabricante de FlexNet Publisher,... • http://www.securityfocus.com/bid/109155 •

CVE-2018-20031
https://notcve.org/view.php?id=CVE-2018-20031
21 Mar 2019 — A Denial of Service vulnerability related to preemptive item deletion in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier allows a remote attacker to send a combination of messages to lmgrd or the vendor daemon, causing the heartbeat between lmgrd and the vendor daemon to stop, and the vendor daemon to shut down. Una vulnerabilidad de denegación de servicio (DoS) relacionada con la eliminación de ítems preferentes en los componentes del demonio lmgrd y del fabricante de ... • http://www.securityfocus.com/bid/109155 •

CVE-2018-20033
https://notcve.org/view.php?id=CVE-2018-20033
25 Feb 2019 — A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat between lmgrd and the vendor daemon to stop. This would force the vendor daemon to shut down. No exploit of this vulnerability has been demonstrated. Una vulnerabilidad de ejecución remota de código en los componentes de lmgrd y del de... • http://www.securityfocus.com/bid/109155 • CWE-770: Allocation of Resources Without Limits or Throttling •