CVE-2024-47856
Last modified
CVE-2024-47856 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that executable instead of the intended executable.. EPSS estimates a 0.49% chance of exploitation in the next 30 days.
Description
In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that executable instead of the intended executable.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rsa | Authentication Agent For Windows | < 7.4.7 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-47856?
How severe is CVE-2024-47856?
How do I fix CVE-2024-47856?
Are you affected by CVE-2024-47856?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
