First published: Thu Jan 30 2025(Updated: )
A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.
Credit: PSIRT-CNA@flexerasoftware.com
Affected Software | Affected Version | How to fix |
---|---|---|
Flexera FlexNet Publisher |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-2658 has been rated as a medium severity vulnerability due to its potential for local privilege escalation.
To fix CVE-2024-2658, update FlexNet Publisher to version 2024 R1 (11.19.6.0) or later.
CVE-2024-2658 affects users of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0).
CVE-2024-2658 is a local privilege escalation vulnerability due to a misconfiguration in lmadmin.exe.
CVE-2024-2658 cannot be exploited remotely as it requires local authentication and low privileges.