IM
IronMonkey Threat Research

CVE-2019-8960 HIGH

Published: 2020-04-21 | Last Modified: 2024-11-21 | Status: Modified

Description

A Denial of Service vulnerability related to command handling has been identified in FlexNet Publisher lmadmin.exe version 11.16.2. The message reading function used in lmadmin.exe can, given a certain message, call itself again and then wait for a further message. With a particular flag set in the original message, but no second message received, the function eventually return an unexpected value which leads to an exception being thrown. The end result can be process termination.

Additional Descriptions (1)

Se ha identificado una vulnerabilidad de Denegación de Servicio relacionada con el manejo de comandos en lmadmin.exe de FlexNet Publisher versión 11.16.2. La función de lectura de mensajes usada en el archivo lmadmin.exe puede, al recibir un determinado mensaje, llamarse así misma y luego esperar un nuevo mensaje. Con un flag particular establecido en el mensaje original, pero sin recibir un segundo mensaje, la función retorna eventualmente un valor inesperado que conlleva a que una excepción sea arrojada. El resultado final puede ser una finalización del proceso.

CVSS Metrics

Base Score: 7.5 (HIGH)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack VectorNETWORK
Attack ComplexityLOW
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactHIGH

Source: [email protected]

Type: Primary

Exploitability Score: 3.9

Impact Score: 3.6

Base Score: 5.0 (MEDIUM)

AV:N/AC:L/Au:N/C:N/I:N/A:P

Access VectorNETWORK
Access ComplexityLOW
AuthenticationNONE
Confidentiality ImpactNONE
Integrity ImpactNONE
Availability ImpactPARTIAL

Source: [email protected]

Type: Primary

Exploitability Score: 10.0

Impact Score: 2.9

Weaknesses

Source Type Description
[email protected] Primary
en CWE-754

Affected Products

Vendor Product Version Update Type
flexera flexnet_publisher 11.16.2 <built-in method update of dict object at 0x7e6110a9ea00> Application

Affected Configurations

Operator: OR

Vulnerable CPE
Yes cpe:2.3:a:flexera:flexnet_publisher:11.16.2:*:*:*:*:*:*:*
Notification
Message here