First published: Wed Dec 11 2019(Updated: )
SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulnerable when configured as a service. This vulnerability may allow an attacker with local access to create, write, and/or delete files in system folder using symbolic links, leading to a privilege escalation. This vulnerability could also be used by an attacker to execute a malicious DLL, which could impact the integrity and availability of the system.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Thales Sentinel LDK | <7.101 | |
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-18232 has been assessed as having a high severity due to the potential for local attackers to exploit file manipulation vulnerabilities.
To mitigate CVE-2019-18232, update the SafeNet Sentinel LDK License Manager to version 7.101 or later.
CVE-2019-18232 affects all versions of SafeNet Sentinel LDK License Manager prior to 7.101 on Microsoft Windows.
CVE-2019-18232 requires local access to the system to exploit the vulnerability.
The impact of CVE-2019-18232 may include unauthorized file creation, modification, or deletion within the system folder.