In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that executable instead of the intended executable.
Metrics
Affected Vendors & Products
References
History
Wed, 26 Nov 2025 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows Rsa Rsa authentication Agent |
|
| Vendors & Products |
Microsoft
Microsoft windows Rsa Rsa authentication Agent |
Tue, 25 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-23 | |
| Metrics |
cvssV3_1
|
Mon, 24 Nov 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that executable instead of the intended executable. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2025-11-24T00:00:00.000Z
Updated: 2025-11-25T14:26:21.347Z
Reserved: 2024-10-04T00:00:00.000Z
Link: CVE-2024-47856
Updated: 2025-11-25T14:26:15.620Z
Status : Awaiting Analysis
Published: 2025-11-24T22:15:46.820
Modified: 2025-11-25T22:16:16.690
Link: CVE-2024-47856
No data.