In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that executable instead of the intended executable.
History

Wed, 26 Nov 2025 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Microsoft
Microsoft windows
Rsa
Rsa authentication Agent
Vendors & Products Microsoft
Microsoft windows
Rsa
Rsa authentication Agent

Tue, 25 Nov 2025 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-23
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Nov 2025 22:00:00 +0000

Type Values Removed Values Added
Description In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that executable instead of the intended executable.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-11-24T00:00:00.000Z

Updated: 2025-11-25T14:26:21.347Z

Reserved: 2024-10-04T00:00:00.000Z

Link: CVE-2024-47856

cve-icon Vulnrichment

Updated: 2025-11-25T14:26:15.620Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-11-24T22:15:46.820

Modified: 2025-11-25T22:16:16.690

Link: CVE-2024-47856

cve-icon Redhat

No data.