ZDI-CAN-22591: ZDI-24-359: Flexera Software FlexNet Publisher Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Flexera Software FlexNet Publisher. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of OpenSSL. The process loads an OpenSSL configuration file from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the service account.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Flexera Software FlexNet Publisher. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-2658.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-22591?
The severity of ZDI-CAN-22591 is significant as it allows local privilege escalation in affected installations of Flexera Software FlexNet Publisher.
How do I fix ZDI-CAN-22591?
To fix ZDI-CAN-22591, users should apply any available security patches or updates released by Flexera Software for FlexNet Publisher.
What kind of attack does ZDI-CAN-22591 enable?
ZDI-CAN-22591 enables local attackers to escalate privileges after executing low-privileged code on the target system.
Which software is affected by ZDI-CAN-22591?
ZDI-CAN-22591 affects Flexera Software FlexNet Publisher installations.
What conditions need to be met to exploit ZDI-CAN-22591?
An attacker must first gain the ability to execute low-privileged code on the target system to exploit ZDI-CAN-22591.