Summary
A local privilege escalation issue could give passage for exploit on Windows, has been reported on an optional service of FlexNet Publisher (FNP), usually used with trusted storage. If you do not depend on FlexNet Licensing Service, there is no impact to you and no further action on your part.
Please see the Symptoms section for more details.
Symptoms
FlexNet Licensing Service on Windows works with an elevated privilege. The elevated privilege allows reading some information required to protect our customers against license misuse and to protect their Intellectual Property. It is possible to use the elevated privilege of FlexNet Publisher with attack vector for exploit on Windows.
A local authenticated user is required in the attack vector and there is no "remote" (aka network vector) vector on this vulnerability. Through standard security measures, as applied in any local environment, the risk of this vulnerability being exploited is considered low.
Originally, the vulnerability and its report utilized a vector that had been mitigated through a change in the Microsoft Windows 10 operating systems, however, we received further updates from the reporter in January 2021 to indicate the existence of more vectors and thus exposing the vulnerability.
Resolution
A complete solution will be available in the upcoming FlexNet Publisher 2021 R3 (11.18.2) release, which is planned for August 2021. We recommend customers upgrade to this version of FlexNet Publisher.
Additional Information
No additional information at this time.
Related Documents
None at this time.
Related Articles
How do You Determine the Current Version of the FlexNet Licensing Service (FNLS) Running on a Windows System? 8Number of Views How to Implement Time-Zone-Based Licensing in FlexNet Licensing 236Number of Views FlexNet Operations 2016 R4 Release Notes 6Number of Views FlexNet Operations Cloud Release Schedule Archive 25Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago