IM
IronMonkey Threat Research

CVE-2016-10395 HIGH

Published: 2017-06-15 | Last Modified: 2026-06-17 | Status: Modified

Description

In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platform, a boundary error related to a named pipe within the FlexNet Publisher Licensing Service can be exploited to cause an out-of-bounds memory read access and subsequently execute arbitrary code with SYSTEM privileges.

Additional Descriptions (1)

En las versiones anteriores a Liton SP1 (11.14.1.1) de FlaxNet Publisher ejecutando FlaxNet Publisher Licensing Service en Windows, un error de limites relacionado al nombre de la tubería dentro de el FlaxNet Publisher Licensing Service puede ser explotado provocando una lectura de memoria fuera de los límites y consecuentemente ejecutar un código aleatorio en los privilegios de SYSTEM.

CVSS Metrics

Base Score: 6.8 (MEDIUM)

AV:L/AC:L/Au:S/C:C/I:C/A:C

Access VectorLOCAL
Access ComplexityLOW
AuthenticationSINGLE
Confidentiality ImpactCOMPLETE
Integrity ImpactCOMPLETE
Availability ImpactCOMPLETE

Source: [email protected]

Type: Primary

Exploitability Score: 3.1

Impact Score: 10.0

Weaknesses

Source Type Description
[email protected] Primary
en CWE-119

Affected Products

Vendor Product Version Update Type
flexerasoftware flexnet_publisher * <built-in method update of dict object at 0x7e60a87b7c80> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:flexerasoftware:flexnet_publisher:*:*:*:*:*:*:*:*

References

Notification
Message here