Input validation error in Floating License Manager - CVE-2014-0759

 

Input validation error in Floating License Manager - CVE-2014-0759

Published: February 28, 2014 / Updated: August 10, 2020


Vulnerability identifier: #VU41987
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2014-0759
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Schneider Electric
Affected software:
Floating License Manager

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Unquoted Windows search path vulnerability in Schneider Electric Floating License Manager 1.0.0 through 1.4.0 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a path that contains a space character. Per: http://cwe.mitre.org/data/definitions/428.html "CWE-428: Unquoted Search Path or Element" Per: http://ics-cert.us-cert.gov/advisories/ICSA-14-058-01 "This license manager is used in the following Schneider Electric products: Power Monitoring Expert, Struxureware process Expert (PES), Struxureware process Expert libraries, Vijeo Citect (SCADA), and Vijeo Citect Historian."


How to mitigate CVE-2014-0759

Install update from vendor's website.

Sources