#VU23431 Link following in SafeNet Sentinel LDK License Manager - CVE-2019-18232
Published: December 6, 2019
SafeNet Sentinel LDK License Manager
Thales Group
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists when the affected product is configured as a service due to improper handling symbolic links. A local user can create, write, and/or delete files in system folder using symbolic links and escalate privileges on the target system.
This vulnerability can also be used by an attacker to execute a malicious DLL, which could impact the integrity and availability of the system.