First published: Thu Jun 15 2017(Updated: )
In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platform, a boundary error related to a named pipe within the FlexNet Publisher Licensing Service can be exploited to cause an out-of-bounds memory read access and subsequently execute arbitrary code with SYSTEM privileges.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Flexera FlexNet Publisher | <=11.14.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-10395 has a high severity rating due to the potential for remote code execution through a boundary error.
To fix CVE-2016-10395, upgrade to FlexNet Publisher version Luton SP1 (11.14.1.1) or later.
CVE-2016-10395 affects FlexNet Publisher versions prior to Luton SP1 running on the Windows platform.
CVE-2016-10395 is a boundary error vulnerability that can lead to out-of-bounds memory read access.
Yes, CVE-2016-10395 can be exploited remotely due to the nature of the vulnerability in the licensing service.