CVE-2018-20033: Flexera Flexnet Publisher
Critical severity, CVSS 9.8. EPSS: 3.7% chance of exploitation in the next 30 days.
A Remote Code Execution vulnerability in lmgrd and vendor daemon components of FlexNet Publisher version 11.16.1.0 and earlier could allow a remote attacker to corrupt the memory by allocating / deallocating memory, loading lmgrd or the vendor daemon and causing the heartbeat between lmgrd and the vendor daemon to stop. This would force the vendor daemon to shut down. No exploit of this vulnerability has been demonstrated.
Affected products
- Flexera Flexnet Publisher: up to and including 11.16.1.0
- Oracle Communications Lsms: from 13.1, up to and including 13.4
Published 2019-02-25. Last modified 2026-06-17.