CVE-2024-2658 vulnerability in Schneider Electric software: risks to industrial control systems

General News

Summary

The article explains CVE-2024-2658 in Schneider Electric Floating License Manager and the FlexNet Publisher component it embeds. A local attacker can place a rogue OpenSSL configuration file at a hardcoded path and force the service to load a malicious DLL. That can lead to code execution in the service context and, under some conditions, privilege escalation to NT AUTHORITY\SYSTEM. The piece also outlines mitigation steps such as upgrading to version 3.0.0.0 or later, tightening folder permissions, and removing the software where floating licenses are not needed.

Classifications

industries
No industries detected
applications
Web and Content Management

AI Classifications

Labels
Software Asset Management SaaS Management Cloud Cost Management

Linked Companies

Flexera
$250M to $500M
Kaspersky Lab
$500M to $1B