Overview of CVE‑2025‑15467
On January 27, 2026, the OpenSSL project published CVE‑2025‑15467, a critical vulnerability (CVSS score: 9.8) affecting OpenSSL versions 3.0 through 3.6. The issue is specific to the Cryptographic Message Syntax (CMS) functionality, particularly in the handling of AuthEnvelopedData structures. Exploitation could potentially result in a stack-based buffer overflow and potential remote code execution.
FlexNet Embedded Impact Assessment
Based on a comprehensive review, we confirm the following:
- FlexNet Embedded Client SDK kits and FlexNet Embedded Local License Servers are not impacted by CVE‑2025‑15467, as the vulnerable code path in OpenSSL is not invoked by FlexNet Embedded components.
- FlexNet Embedded Local License Servers do not use OpenSSL’s CMS or SMIME APIs. FlexNet Embedded Local License Server 2025.09 has been explicitly verified to avoid CMS-related APIs.
- Password-based CMS encryption is not used in any FlexNet Embedded components.
Required Customer Action
At the time of this assessment, no action is required by FlexNet Embedded customers or their end users.
Planned Update
As the vulnerability does not affect FlexNet Embedded Local License Server of Client SDK kits, no hotfix is required for existing FlexNet Embedded versions.
OpenSSL version 3.5.5, which includes the fix for CVE‑2025‑15467 will be included in the following FlexNet Embedded releases as part of our ongoing dependency maintenance:
- FlexNet Embedded Local License Server 2026.03
- FlexNet Embedded Client SDK kits 2026.09
Related Articles
CVE-2019-17571: Log4j vulnerability impact on FlexNet Embedded 5Number of Views INDEX: Log4j vulnerability impact on FlexNet Embedded 17Number of Views Log4j Vulnerability Impact on FlexNet Embedded (CVE-2021-4104) 14Number of Views CVE-2021-44228: Log4j vulnerability impact on FlexNet Embedded 20Number of Views Vulnerability: CVE-2021-44832 Log4j vulnerability impact on FlexNet Publisher 20Number of Views
Hi, I am Reva - Ask me anything.
No new updates
Thanks for the feedback!
Your feedback has been saved.Rate this response:
Add Additional feedback ( Optional )
Are you sure you want to cancel
the case creation?
Are you sure you want to cancel the case creation?
Are you sure you want to close this case
| Products | Region | Phone Numbers |
|---|---|---|
| FlexNet Operations FlexNet Embedded FlexNet Publisher FlexNet Connect FlexNet Code Insight InstallAnywhere InstallShield |
North America * |
+1 630-332-2513 (toll) +1 877-279-2853 (toll-free in North America) |
| Europe * |
+44 1925 944367 (toll) +44 800 047 8642 (toll-free in Europe) |
|
| Japan * | +81 3-4540-5335 (select option 2) | |
| Australia * |
+61 3 9895 2177 +61 1800 560 603 (toll-free in Australia) |
|
|
Usage Intelligence (formerly
Revulytics) Compliance Intelligence |
Please use the Case Portal to submit your support ticket or reach out to your Revenera contact. | |
Case id: 00001065
Activity: Status change: 2 hours ago