Thales SafeNet Authentication Client vulnerability allows local SYSTEM level execution via exploit
CVE-2023-7016

7.8HIGH

Key Information:

Vendor

Thales

Vendor
CVE Published:
27 February 2024

Badges

πŸ‘Ύ Exploit Exists🟑 Public PoCπŸ“° News Worthy

What is CVE-2023-7016?

A vulnerability exists within the Thales SafeNet Authentication Client prior to version 10.8 R10, allowing local attackers to gain unauthorized access and execute code at the SYSTEM level. This flaw poses significant risks to systems relying on this authentication solution, making it crucial for organizations to update to the latest version and mitigate potential threats.

Affected Version(s)

SafeNet Authentication Client Windows 0 < 10.8

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

CVE-2023-7016 | Vulnerabilities

A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to ex

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • πŸ“°

    First article discovered by yitian.ir

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kravets Vasiliy, xi-tauw@xi-tauw.info
.