7.2
CVSSv2

CVE-2021-42056

Published: 24/06/2022 Updated: 06/07/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.7 | Impact Score: 5.9 | Exploitability Score: 0.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Thales Safenet Authentication Client (SAC) for Linux and Windows up to and including 10.7.7 creates insecure temporary hid and lock files allowing a local attacker, through a symlink attack, to overwrite arbitrary files, and potentially achieve arbitrary command execution with high privileges.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

thalesgroup safenet_authentication_client

Github Repositories

Safenet Authentication Client Privilege Escalation - CVE-2021-42056

Safenet Authentication Client Privilege Escalation CVE-2021-42056 Based on Thales' website [1], SafeNet Authentication Client – is a middleware client that manages Thales' extensive SafeNet portfolio of certificate-based authenticators, including eTokens, SafeNet IDPrime smart cards, USB and software-based devices Improper permissions have been set on multiple