CVE Vulnerabilities

CVE-2023-7016

Improper Privilege Management

Published: Feb 27, 2024 | Modified: Mar 04, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Safenet_authentication_clientThalesgroup*10.8 (excluding)
Safenet_authentication_clientThalesgroup10.8 (including)10.8 (including)
Safenet_authentication_clientThalesgroup10.8-r1 (including)10.8-r1 (including)
Safenet_authentication_clientThalesgroup10.8-r5 (including)10.8-r5 (including)
Safenet_authentication_clientThalesgroup10.8-r6 (including)10.8-r6 (including)
Safenet_authentication_clientThalesgroup10.8-r8 (including)10.8-r8 (including)
Safenet_authentication_clientThalesgroup10.8-r9 (including)10.8-r9 (including)

Potential Mitigations

References