Autodesk: Possible vulnerability revenera “CVE-2024-2658: FlexNet Publisher potential local privilege escalation issue”

Issue:
Autodesk: revenera CVE-2024-2658: FlexNet Publisher potential local privilege escalation issue.
potential vulnerability has been identified in FlexNet Publisher.

https://community.flexera.com/t5/FlexNet-Publisher-Knowledge-Base/CVE-2024-2658-FlexNet-Publisher-potential-local-privilege/ta-p/313003/jump-to/first-unread-message


Causes:
Possible vulnerability.


Solution:

Autodesk Statement
•    According to Revenera's article, the vulnerability is restricted to lmadmin.exe (affected module) which Autodesk doesn’t ship or use as part of the Network License Manager (NLM) installer to customers.  Hence the shipped LMTOOLS is not affected by the vulnerability and doesn't require an immediate upgrade to the version 11.19.6

•    Producers utilizing the vendor daemon with secure communications (TLS communications) enabled prior to FlexNet Publisher version 2024 R1: This vulnerability could affect producers who are using a secured communication protocol. However, it does not impact the Autodesk vendor daemon (adskflex.exe) as Autodesk does not currently support or use secured communications.

About the Author

Jeff Arbogast

Manufacturing Solution Center Team Lead<br><br>Jeff is responsible for manufacturing Technical Support for both internal staff and customers. In addition to the daily activities of the support center, he helps write for the National Support Center blog, and has written online classes for the IMAGINiT training on demand site.

Follow on Linkedin More Content by Jeff Arbogast
Previous Article
Vault Item Number Rename
Vault Item Number Rename

How to change the Item Number when using the "Mapped" Item Number Schema

Next Article
Uninstall an Autodesk product when the Custom Install Deployment is no longer available
Uninstall an Autodesk product when the Custom Install Deployment is no longer available

You want to uninstall an Autodesk product but the original deployment package is no longer available in the...

Need tech support? Let us help!

Learn More