CVE-2024-0197

HIGH

Thales SafeNet Sentinel HASP LDK < 9.16 - Privilege Escalation via Installer

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-0197. PoCs published by ewilded.

AI-analyzed exploit summary This repository contains a functional proof-of-concept for CVE-2024-0197, a local privilege escalation vulnerability in Thales Sentinel HASP LDK. The exploit leverages DLL search order hijacking by placing a proxy DLL (fltlib.dll) in a known location, which is then loaded by msiexec.exe to achieve SYSTEM privileges.

Description

A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via local access.

Exploits (1)

nomisec WORKING POC 3 stars
by ewilded · poc
https://github.com/ewilded/CVE-2024-0197-POC

This repository contains a functional proof-of-concept for CVE-2024-0197, a local privilege escalation vulnerability in Thales Sentinel HASP LDK. The exploit leverages DLL search order hijacking by placing a proxy DLL (fltlib.dll) in a known location, which is then loaded by msiexec.exe to achieve SYSTEM privileges.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: Thales Sentinel HASP LDK
No auth needed
Prerequisites: Access to the local system · Ability to place files in AppData\Local\Temp
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0043
EPSS Percentile 34.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
thalesgroup/sentinel_hasp_ldk < 9.16
Published Feb 27, 2024
Tracked Since Feb 18, 2026