CVE-2016-10395
Estado: ModificadaAlta (7.8)—
In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platform, a boundary error related to a named pipe within the FlexNet Publisher Licensing Service can be exploited to cause an out-of-bounds memory read access and subsequently execute arbitrary code with SYSTEM privileges.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.40%
- Percentil entre todas las CVEs puntuadas: 32
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-119
Referencias
- https://ics-cert.us-cert.gov/advisories/ICSA-18-144-01
- https://secuniaresearch.flexerasoftware.com/advisories/76368/
- https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9134-vulnerabilities-within-schneider-electric-floating-license-manager
- https://www.schneider-electric.com/en/download/document/SEVD-2018-046-01/
- https://www.schneider-electric.com/en/download/document/SEVD-2018-137-01/
- https://www.schneider-electric.com/en/download/document/SEVD-2018-144-01/
- https://ics-cert.us-cert.gov/advisories/ICSA-18-144-01
- https://secuniaresearch.flexerasoftware.com/advisories/76368/
- https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9134-vulnerabilities-within-schneider-electric-floating-license-manager
- https://www.schneider-electric.com/en/download/document/SEVD-2018-046-01/
- https://www.schneider-electric.com/en/download/document/SEVD-2018-137-01/
- https://www.schneider-electric.com/en/download/document/SEVD-2018-144-01/
JSON original (NVD)
Mostrar
{
"id": "CVE-2016-10395",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:S/C:C/I:C/A:C",
"authentication": "SINGLE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.1,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "PSIRT-CNA@flexerasoftware.com",
"affectedData": [
{
"vendor": "Flexera Software LLC",
"product": "FlexNet Publisher",
"versions": [
{
"status": "affected",
"version": "Versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platform"
}
]
}
]
}
],
"published": "2017-06-15T16:29:00.187",
"references": [
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-144-01",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "https://secuniaresearch.flexerasoftware.com/advisories/76368/",
"tags": [
"Permissions Required",
"Third Party Advisory"
],
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9134-vulnerabilities-within-schneider-electric-floating-license-manager",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "https://www.schneider-electric.com/en/download/document/SEVD-2018-046-01/",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "https://www.schneider-electric.com/en/download/document/SEVD-2018-137-01/",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "https://www.schneider-electric.com/en/download/document/SEVD-2018-144-01/",
"source": "PSIRT-CNA@flexerasoftware.com"
},
{
"url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-144-01",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://secuniaresearch.flexerasoftware.com/advisories/76368/",
"tags": [
"Permissions Required",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.citect.schneider-electric.com/safety-and-security-central/36-security-notifications/9134-vulnerabilities-within-schneider-electric-floating-license-manager",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.schneider-electric.com/en/download/document/SEVD-2018-046-01/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.schneider-electric.com/en/download/document/SEVD-2018-137-01/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.schneider-electric.com/en/download/document/SEVD-2018-144-01/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-119"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platform, a boundary error related to a named pipe within the FlexNet Publisher Licensing Service can be exploited to cause an out-of-bounds memory read access and subsequently execute arbitrary code with SYSTEM privileges."
},
{
"lang": "es",
"value": "En las versiones anteriores a Liton SP1 (11.14.1.1) de FlaxNet Publisher ejecutando FlaxNet Publisher Licensing Service en Windows, un error de limites relacionado al nombre de la tubería dentro de el FlaxNet Publisher Licensing Service puede ser explotado provocando una lectura de memoria fuera de los límites y consecuentemente ejecutar un código aleatorio en los privilegios de SYSTEM."
}
],
"lastModified": "2026-06-17T00:39:35.683",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:flexerasoftware:flexnet_publisher:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "27B21AC4-B047-470E-BE67-A503B6E935A9",
"versionEndIncluding": "11.14.1"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "The vulnerability has been analyzed by us as to be exploitable through a locally authenticated user solely in this context. Thus, we assigned the following CVSS metrics and scores for the vulnerability with the CVE identifier CVE-2016-10395: <br /> CVSS version 2: AV:L/AC:L/Au:S/C:C/I:C/A:C/E:POC/RL:OF/RC:C <br /> CVSS version 3: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C",
"lastModified": "2017-08-16T13:15:04.617",
"organization": "Flexera Software"
}
],
"sourceIdentifier": "PSIRT-CNA@flexerasoftware.com"
}