Summary
An elevated privilege vulnerability was discovered in the FlexNet Publisher License Server. This article provides details about the vulnerability as well as mitigation and remediation options.
Description
This elevated privilege vulnerability, if exploited, may allow bypassing the lmgrd -2 -p -local option used to restrict license server administration to a local license administrator. The impact of this could result in license server disruption by an unauthorized user. All versions of FlexNet Publisher are susceptible to this issue.
Workaround
Producers may use the -x license server option to mitigate the issue. The -x option disables certain commands to be executed on the lmgrd/vendor daemon. It can only be applied to lmdown and lmremove commands:
-x lmdownoption disableslmdowncommand on the lmgrd, preventing unauthorized license server shutdowns.-x lmremoveoption disableslmremovecommand on the vendor daemon.
We recommend users review the License Server Manager “lmgrd” section of the FlexNet Publisher License Administration Guide for details about the -x option. This document is available on the Revenera Documentation Site, docs.revenera.com.
Resolution
This vulnerability is remediated in FlexNet Publisher 2022 R3 (11.19.2.0) or greater. Users will need to upgrade their lmgrd to this version or higher.
Additional Information
Revenera knows of no exploits of this vulnerability in production deployments.
For identifying this vulnerability and disclosing it to Revenera under a responsible disclosure process, we'd like to thank the team members at Rapid7.
Related Articles
Elevated Privilege Issue with FlexNet Publisher Licensing Service on Windows 9Number of Views FlexNet Publisher versus FlexNet Embedded license server 18Number of Views CVE-2024-2658: FlexNet Publisher potential local privilege escalation issue 15Number of Views Can The FlexNet Publisher License Server Serve A Flex Enabled Client Application Over DirectAccess? 8Number of Views Building an Installer for FlexNet Publisher License Server 6Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Revenera Assistant
Case id: 00001065
Activity: Status change: 2 hours ago