CVE Database
/

CVE-2024-2658

Back to search

CVE-2024-2658

Published: Jan 30, 2025

Modified: Jan 30, 2025

PUBLISHED

Description

A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.

VendorProductVersions

Flexera

FlexNet Publisher

affected
0 - < 2024 R1 (11.19.6.0)

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now