AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2024-47856

CRITICAL · CVSS 9.8 EPSS 0.54%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2025-11-24 · Last synced 2026-08-04

CyberRota Analysis

This is a critical severity vulnerability with a CVSS score of 9.8. It affects Windows.

CVE
CVE-2024-47856
Severity
CRITICAL
CVSS
9.8
EPSS
0.54%
Windows

Original NVD Description

In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the path has one or more spaces and is not surrounded by quotation marks. An adversary can place an executable in a higher-level directory of the path, and Windows will resolve that executable instead of the intended executable.

Related CVEs

Other vulnerabilities affecting the same vendor(s)