PT-2025-47969 · Rsa · Rsa Authentication Agent
Published
2025-11-24
·
Updated
2025-12-30
·
CVE-2024-47856
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RSA Authentication Agent versions prior to 7.4.7
Description
The RSA Authentication Agent is susceptible to a path interception issue affecting service paths and shortcut paths. This occurs when a path contains spaces and is not enclosed in quotation marks. An attacker can exploit this by placing an executable in a directory higher in the path structure, causing Windows to execute the malicious file instead of the intended one.
Recommendations
Update to version 7.4.7 or later.
Fix
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rsa Authentication Agent