Back to search
CVE-2024-2658
Published: Jan 30, 2025
Modified: Jan 30, 2025
PUBLISHED
Description
A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.
| Vendor | Product | Versions |
|---|---|---|
Flexera | FlexNet Publisher | affected 0 - < 2024 R1 (11.19.6.0) |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now