CVE-2024-47856

CRITICAL

RSA Authentication Agent <7.4.7 - Path Traversal

Title source: llm
STIX 2.1

Description

In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that executable instead of the intended executable.

Scores

CVSS v3 9.8
EPSS 0.0014
EPSS Percentile 33.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-23
Status published
Products (1)
rsa/authentication_agent_for_windows < 7.4.7
Published Nov 24, 2025
Tracked Since Feb 18, 2026