7.8

CVE-2023-7016

Privilege Escalation in SafeNet Authentication Client

A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Thalesgroup ≫ Safenet Authentication Client Version < 10.8
   Microsoft ≫ Windows Version -
Thalesgroup ≫ Safenet Authentication Client Version 10.8 Update -
   Microsoft ≫ Windows Version -
Thalesgroup ≫ Safenet Authentication Client Version 10.8 Update r1
   Microsoft ≫ Windows Version -
Thalesgroup ≫ Safenet Authentication Client Version 10.8 Update r5
   Microsoft ≫ Windows Version -
Thalesgroup ≫ Safenet Authentication Client Version 10.8 Update r6
   Microsoft ≫ Windows Version -
Thalesgroup ≫ Safenet Authentication Client Version 10.8 Update r8
   Microsoft ≫ Windows Version -
Thalesgroup ≫ Safenet Authentication Client Version 10.8 Update r9
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.34% 0.257
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
psirt@thalesgroup.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.