CVE-2018-20033
Last modified
CVE-2018-20033 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat between lmgrd and the vendor daemon to stop. This would force the vendor daemon to shut down. EPSS estimates a 3.67% chance of exploitation in the next 30 days.
Description
A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat between lmgrd and the vendor daemon to stop. This would force the vendor daemon to shut down. No exploit of this vulnerability has been demonstrated.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Flexera | Flexnet Publisher | <= 11.16.1.0 |
| Oracle | Communications Lsms | >= 13.1, <= 13.4 |
References
- http://www.securityfocus.com/bid/109155Broken Link
- https://secuniaresearch.flexerasoftware.com/advisories/85979/Not Applicable, Vendor Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/109155Broken Link
- https://secuniaresearch.flexerasoftware.com/advisories/85979/Not Applicable, Vendor Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-20033?
How severe is CVE-2018-20033?
How do I fix CVE-2018-20033?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-20027The yaml_parse.load method in Pylearn2 allows code injection…
- CVE-2018-20028Contao 3.x before 3.5.37, 4.4.x before 4.4.31 and 4.6.x befo…
- CVE-2018-20029The nxfs.sys driver in the DokanFS library 0.6.0 in NoMachin…5.5
- CVE-2018-20030An error when processing the EXIF_IFD_INTEROPERABILITY and E…
- CVE-2018-20031A Denial of Service vulnerability related to preemptive item…7.5
- CVE-2018-20032A Denial of Service vulnerability related to message decodin…7.5
- CVE-2018-20034A Denial of Service vulnerability related to adding an item …7.5
- CVE-2018-2004IBM Jazz Reporting Service (JRS) 6.0 through 6.0.6 is vulner…5.4
- CVE-2018-2005IBM BigFix Platform 9.2 and 9.5 stores potentially sensitive…3.3
- CVE-2018-20050Mishandling of an empty string on the Jooan JA-Q1H Wi-Fi cam…
- CVE-2018-20051Mishandling of '>' on the Jooan JA-Q1H Wi-Fi camera with fir…
- CVE-2018-20052An issue was discovered on Cerner Connectivity Engine (CCE) …
Are you affected by CVE-2018-20033?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
