CVE-2016-10395
Summary
| CVE | CVE-2016-10395 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-15 16:29:00 UTC |
| Updated | 2018-05-30 01:29:00 UTC |
| Description | In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platform, a boundary error related to a named pipe within the FlexNet Publisher Licensing Service can be exploited to cause an out-of-bounds memory read access and subsequently execute arbitrary code with SYSTEM privileges. |
NVD Known Affected Configurations (CPE 2.3)
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|
| Flexera Software | 2017-08-16 | Flexera Software | The vulnerability has been analyzed by us as to be exploitable through a locally authenticated user solely in this context. Thus, we assigned the following CVSS metrics and scores for the vulnerability with the CVE identifier CVE-2016-10395: <br /> CVSS version 2: AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:OF/RC:C <br /> CVSS version 3: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C |
Legacy QID Mappings
- 590723 Schneider Electric Floating License Manager for CitectSCADA,CitectHistorian and Citect Anywhere Multiple Vulnerabilities (ICSA-18-144-01)