CVE-2021-44153
Reprise License Manager 14.2 Remote Binary Execution
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
An issue was discovered in Reprise RLM 14.2. When editing the license file, it is possible for an admin user to enable an option to run arbitrary executables, as demonstrated by an ISV demo "C:\Windows\System32\calc.exe" entry. An attacker can exploit this to run a malicious binary on startup, or when triggering the Reread/Restart Servers function on the webserver. (Exploitation does not require CVE-2018-15573, because the license file is meant to be changed in the application.)
Se ha detectado un problema en Reprise RLM versión 14.2. Al editar el archivo de licencia, es posible que un usuario administrador habilite una opción para ejecutar ejecutables arbitrarios, como lo demuestra una entrada de demostración ISV "C:\Windows\System32\calc.exe". Un atacante puede explotar esto para ejecutar un binario malicioso en el inicio, o cuando es activada la función Reread/Restart Servers en el servidor web. (La explotación no requiere CVE-2018-15573, porque el archivo de licencia está destinado a ser cambiado en la aplicación)
Reprise License Manager version 14.2 suffers from an authenticated remote binary execution vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-11-22 CVE Reserved
- 2021-12-08 CVE Published
- 2021-12-08 First Exploit
- 2024-08-04 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://packetstorm.news/files/id/165194 | 2021-12-08 | |
http://packetstormsecurity.com/files/165194/Reprise-License-Manager-14.2-Remote-Binary-Execution.html | 2024-08-04 |
URL | Date | SRC |
---|---|---|
https://reprisesoftware.com/admin/rlm-admin-download.php?&euagree=yes | 2021-12-15 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Reprisesoftware Search vendor "Reprisesoftware" | Reprise License Manager Search vendor "Reprisesoftware" for product "Reprise License Manager" | 14.2 Search vendor "Reprisesoftware" for product "Reprise License Manager" and version "14.2" | - |
Affected
|