First published: Tue Sep 25 2012(Updated: )
The authentication functionality in EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 on Windows XP and Windows Server 2003, when an unspecified configuration exists, allows remote authenticated users to bypass an intended token-authentication step, and establish a login session to a remote host, by leveraging Windows credentials for that host.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
EMC RSA Authentication Agent SDK for C | =7.1 | |
RSA Authentication Client | =3.5 | |
Microsoft Windows Server | ||
Microsoft Windows XP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-2287 is classified as a medium severity vulnerability.
To fix CVE-2012-2287, update the EMC RSA Authentication Agent to version 7.1 or the RSA Authentication Client to version 3.5 if applicable.
CVE-2012-2287 affects users of EMC RSA Authentication Agent 7.1 and RSA Authentication Client 3.5 running on Windows XP and Windows Server 2003.
Attackers can bypass the intended token-authentication step, allowing unauthorized login sessions.
Yes, CVE-2012-2287 can be exploited by remote authenticated users.