SB2019120601 - Privilege escalation in Thales DIS SafeNet Sentinel LDK License Manager
Published: December 6, 2019
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Link following (CVE-ID: CVE-2019-18232)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists when the affected product is configured as a service due to improper handling symbolic links. A local user can create, write, and/or delete files in system folder using symbolic links and escalate privileges on the target system.
This vulnerability can also be used by an attacker to execute a malicious DLL, which could impact the integrity and availability of the system.
Remediation
Install update from vendor's website.