CVE-2017-6885
An error when handling certain external commands and services related to the FlexNet Inventory Agent and FlexNet Beacon of the Flexera Software FlexNet Manager Suite 2017 before 2017 R1 and 2014 R3 through 2016 R1 SP1 can be exploited to gain elevated…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An error when handling certain external commands and services related to the FlexNet Inventory Agent and FlexNet Beacon of the Flexera Software FlexNet Manager Suite 2017 before 2017 R1 and 2014 R3 through 2016 R1 SP1 can be exploited to gain elevated privileges.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.17% probability · 66th percentile
- CISA KEV
- Not listed
- Affected
- flexerasoftware/flexnet manager suite
- Source
- PSIRT-CNA@flexerasoftware.com
References
- https://secuniaresearch.flexerasoftware.com/advisories/76223/Permissions Required
- https://secuniaresearch.flexerasoftware.com/advisories/76223/Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.