cbcvebase.
CVE-2018-20033
published 2019-02-25

CVE-2018-20033: A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to…

PriorityP259critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
3.67%
88.3th percentile
A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat between lmgrd and the vendor daemon to stop. This would force the vendor daemon to shut down. No exploit of this vulnerability has been demonstrated.

Affected

3 ranges
VendorProductVersion rangeFixed in
flexeraflexnet_publisher<= 11.16.1.0
flexera_software_llcflexnet_publisher
oraclecommunications_lsms13.1 – 13.4

Detection & IOCsextracted from sources · hover to see the quote

  • Target processes for CVE-2018-20033 are lmgrd and vendor daemon components of FlexNet Publisher; monitor for memory corruption activity (allocating/deallocating memory) involving these processes that causes the heartbeat between lmgrd and the vendor daemon to stop
  • Monitor lmadmin and vendor daemon components for unexpected shutdowns triggered by memory corruption; the attack pattern involves allocating/deallocating memory and disrupting the heartbeat mechanism between lmadmin and the vendor daemon
  • Alert on unexpected vendor daemon shutdowns following network-originated messages to lmgrd or lmadmin; the vulnerability is exploitable remotely with low skill level and no authentication required (CVSS AV:N/AC:L/PR:N/UI:N)
  • Researcher attribution: Sergey Temnikov of Kaspersky reported these vulnerabilities; monitor threat intelligence feeds from Kaspersky for any associated exploit tooling
  • ·No exploit has been publicly demonstrated for CVE-2018-20033; no known public exploits specifically target this vulnerability as of the advisory dates
  • ·No known public exploits specifically target these vulnerabilities, limiting the availability of concrete exploit-based IOCs

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.