PT-2026-6558 · Thales · Safenet Agent For Windows Logon

Published

2026-02-05

·

Updated

2026-02-13

·

CVE-2026-0872

CVSS v4.0

5.6

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions Thales SafeNet Agent for Windows Logon versions 4.0.0 through 4.1.2
Description A flaw exists in the certificate validation process within SafeNet Agent for Windows Logon on Windows, potentially enabling signature spoofing. This issue stems from an insecure Active Directory Certificate Services (AD CS) certificate template configuration, which could allow an authenticated user to escalate privileges to Domain Admin.
Recommendations Update SafeNet Agent for Windows Logon to a version later than 4.1.2.

Fix

LPE

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2026-0872

Affected Products

Safenet Agent For Windows Logon