Denial of Service Vulnerability in FlexNet Publisher by Flexera
CVE-2019-8961

7.5HIGH

Key Information:

Vendor

Flexera

Vendor
CVE Published:
21 April 2020

What is CVE-2019-8961?

A Denial of Service vulnerability has been discovered in FlexNet Publisher's lmadmin.exe version 11.16.2. The issue arises from the recursive nature of the message reading function, which can be exploited by an unauthenticated remote attacker. By sending specifically crafted messages that trigger this recursion, attackers can induce a stack exhaustion condition, effectively disrupting service availability.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.