CVE-2018-20033 is a critical remote code execution vulnerability affecting FlexNet Publisher versions 11.16.1.0 and earlier, as well as Flexera and Oracle products utilizing these components. This flaw allows a remote attacker to corrupt memory, potentially leading to the shutdown of vendor daemons. With a CVSS score of 9.8 (Critical), it presents a high risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While no active exploits have been demonstrated and no public exploit code exists, the vulnerability has garnered significant community discussion, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 11.16.1.0CPE matchmatch criteria | cpe:2.3:a:flexera:flexnet_publisher:*:*:*:*:*:*:*:* | ||
>= 13.1, <= 13.4CPE matchmatch criteria | cpe:2.3:a:oracle:communications_lsms:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.