AI description
CVE-2024-2658 describes a misconfiguration within the `lmadmin.exe` component of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0). This flaw allows the OpenSSL configuration file to be loaded from a directory that does not exist. An unauthorized, locally authenticated user with low privileges can exploit this by creating the non-existent directory and placing a specially crafted `openssl.conf` file within it. This action can lead to the execution of a malicious Dynamic-Link Library (DLL) with elevated privileges on the affected system.
- Description
- A misconfiguration in lmadmin.exe of FlexNet Publisher versions prior to 2024 R1 (11.19.6.0) allows the OpenSSL configuration file to load from a non-existent directory. An unauthorized, locally authenticated user with low privileges can potentially create the directory and load a specially crafted openssl.conf file leading to the execution of a malicious DLL (Dynamic-Link Library) with elevated privileges.
- Source
- PSIRT-CNA@flexerasoftware.com
- NVD status
- Deferred
CVSS 4.0
- Type
- Secondary
- Base score
- 8.5
- Impact score
- -
- Exploitability score
- -
- Vector string
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity
- HIGH
- PSIRT-CNA@flexerasoftware.com
- CWE-427
Hype score is a measure of social media activity compared against trending CVEs from the past 12 months. Max score 100.
- Hype score
3
The CVE-2024-2658 vulnerability was discovered in 2024 within the FlexNet Publisher component of the Schneider Electric Floating License Manager. This software handles license management across various Schneider Electric products used for comprehensive industrial automation https
@kaspersky
26 Jun 2026
1362 Impressions
1 Retweet
5 Likes
0 Bookmarks
0 Replies
0 Quotes
Actively exploited CVE : CVE-2024-2658
@transilienceai
13 Feb 2025
10 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2024-2658
@transilienceai
10 Feb 2025
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2024-2658
@transilienceai
9 Feb 2025
18 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2024-2658
@transilienceai
9 Feb 2025
13 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
Actively exploited CVE : CVE-2024-2658
@transilienceai
7 Feb 2025
8 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes