In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that executable instead of the intended executable.
Metrics
Affected Vendors & Products
References
History
Tue, 30 Dec 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rsa authentication Agent For Windows
|
|
| CPEs | cpe:2.3:a:rsa:authentication_agent_for_windows:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rsa authentication Agent For Windows
|
Wed, 26 Nov 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows Rsa Rsa authentication Agent |
|
| Vendors & Products |
Microsoft
Microsoft windows Rsa Rsa authentication Agent |
Tue, 25 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-23 | |
| Metrics |
cvssV3_1
|
Mon, 24 Nov 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that executable instead of the intended executable. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-24T00:00:00.000Z
Updated: 2025-11-25T14:26:21.347Z
Reserved: 2024-10-04T00:00:00.000Z
Link: CVE-2024-47856
Updated: 2025-11-25T14:26:15.620Z
Status : Analyzed
Published: 2025-11-24T22:15:46.820
Modified: 2025-12-30T17:25:32.607
Link: CVE-2024-47856
No data.