First published: Fri Mar 02 2018(Updated: )
SafeNet Authentication Service Windows Logon Agent uses a weak ACL for unspecified installation directories and executable modules, which allows local users to gain privileges by modifying an executable module, a different vulnerability than CVE-2015-7965.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Gemalto Safenet Authentication Service |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7966 has a medium severity rating due to its potential for privilege escalation.
To fix CVE-2015-7966, update the SafeNet Authentication Service Windows Logon Agent to the latest version provided by Gemalto.
CVE-2015-7966 affects local users of the Gemalto SafeNet Authentication Service Windows Logon Agent who can modify executable modules.
The impact of CVE-2015-7966 allows local users to gain higher privileges on affected systems.
A potential workaround for CVE-2015-7966 is to restrict access to the installation directories and executable modules.