Thales Safenet Authentication Client (SAC) for Linux and Windows through 10.7.7 creates insecure temporary hid and lock files allowing a local attacker, through a symlink attack, to overwrite arbitrary files, and potentially achieve arbitrary command execution with high privileges.
2022-06-24T17:15:08.467
2024-11-21T06:27:09.527
Modified
CVSSv3.1: 6.7 (MEDIUM)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | thalesgroup | safenet_authentication_client | ≤ 10.7.7 | Yes |
Operating System | linux | linux_kernel | - | No |
Operating System | microsoft | windows | - | No |