CVE-2015-8277

CRITICAL

Flexera FlexNet Publisher <11.13.1.2 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-8277. PoCs published by securifera.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2015-8277, targeting the Flexera License Manager (lmgrd) bundled with ArcGIS 10.3.1. The exploit uses a brute-force ROP chain to achieve remote code execution on Windows 7 x86 systems.

Description

Multiple buffer overflows in (1) lmgrd and (2) Vendor Daemon in Flexera FlexNet Publisher before 11.13.1.2 Security Update 1 allow remote attackers to execute arbitrary code via a crafted packet with opcode (a) 0x107 or (b) 0x10a.

Exploits (1)

nomisec WORKING POC 3 stars
by securifera · poc
https://github.com/securifera/CVE-2015-8277-Exploit

This repository contains a functional proof-of-concept exploit for CVE-2015-8277, targeting the Flexera License Manager (lmgrd) bundled with ArcGIS 10.3.1. The exploit uses a brute-force ROP chain to achieve remote code execution on Windows 7 x86 systems.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Flexera License Manager (lmgrd) version 11.12.1.2 (bundled with ArcGIS 10.3.1)
No auth needed
Prerequisites: Network access to the target system · Target system running Windows 7 x86 · Flexera License Manager (lmgrd) version 11.12.1.2
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1035266
Vendor Advisory x_refsource_confirm
http://support.citrix.com/article/CTX207824
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/485744
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/83334
Various Sources x_refsource_misc
https://www.securifera.com/advisories/cve-2015-8277

Scores

CVSS v3 9.8
EPSS 0.7756
EPSS Percentile 99.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
flexerasoftware/flexnet_publisher < 11.13.1.0
Published Feb 24, 2016
Tracked Since Feb 18, 2026