Back to overview

CVE-2024-47856

CRITICAL
9.8
CVSS 3.1
Description
In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that executable instead of the intended executable.

Metadata

CVE ID
CVE-2024-47856
State
PUBLISHED
Assigner
mitre
Reserved
2024-10-04 00:00 UTC
Published
2025-11-24 00:00 UTC
Last updated
2025-11-25 14:26 UTC
Primary CWE
CWE-23
CWE-23 Relative Path Traversal
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CWE-23 adp CWE-23 Relative Path Traversal
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview