First published: Fri Mar 02 2018(Updated: )
SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability than CVE-2015-7966.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gemalto Safenet Authentication Service |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7965 is classified as a medium severity vulnerability due to its potential to allow local users to gain elevated privileges.
To mitigate CVE-2015-7965, ensure that the access control list (ACL) permissions for the installation directories and executable modules are properly configured to restrict unauthorized access.
CVE-2015-7965 affects users of the Gemalto SafeNet Authentication Service Windows Logon Agent.
CVE-2015-7965 is a privilege escalation vulnerability that arises from weak ACL settings.
CVE-2015-7965 cannot be exploited remotely; it requires local access to the affected system.