ZDI-24-359: Flexera Software FlexNet Publisher Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Flexera Software FlexNet Publisher. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of OpenSSL. The process loads an OpenSSL configuration file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Flexera Software FlexNet Publisher. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-2658.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-359?
The severity of ZDI-24-359 is classified as a privilege escalation vulnerability.
How do I fix ZDI-24-359?
To fix ZDI-24-359, update to the latest version of Flexera Software FlexNet Publisher that addresses this specific vulnerability.
Who is affected by the ZDI-24-359 vulnerability?
The ZDI-24-359 vulnerability affects all installations of Flexera Software FlexNet Publisher that are running vulnerable versions.
What type of attack does ZDI-24-359 enable?
ZDI-24-359 enables local attackers to escalate their privileges on affected systems.
What is required to exploit ZDI-24-359?
An attacker must first gain the ability to execute low-privileged code on the system to exploit ZDI-24-359.