CVE-2021-47859
7.8HID Global · ActivIdentity
ActivIdentity 8.2 is vulnerable to an unquoted service path flaw in the ac.sharedstore service, which allows local attackers to execute arbitrary code and escalate system privileges.
Executive summary
A local privilege escalation vulnerability in HID Global ActivIdentity 8.2 allows attackers to gain system-level access by exploiting an unquoted service path.
Vulnerability
The software contains an unquoted service path vulnerability in the ac.sharedstore service. This flaw allows a local, authenticated attacker to place a malicious executable in a parent directory of the service path, which the service will then execute with elevated privileges.
Business impact
The ability for a local user to escalate privileges to LocalSystem status poses a severe risk to organizational security. Successful exploitation could lead to full system compromise, unauthorized access to sensitive credential data handled by the smart card software, and the potential for lateral movement within the network. The CVSS score of 7.8 reflects the high severity of this local access vulnerability.
Remediation
Immediate Action: Upgrade to a version of ActivIdentity that resolves this service path configuration issue, or contact HID Global support if a patch is not directly available for your specific deployment.
Proactive Monitoring: Review system logs for unauthorized file creation attempts within the C:\Program Files\Common Files\ActivIdentity directory.
Compensating Controls: Ensure that standard users are restricted from writing to the directory path C:\Program Files\Common Files\ActivIdentity, as this will prevent the placement of malicious binaries required to trigger the exploit.
Exploitation status
Public Exploit Available: Yes, a published proof-of-concept exists via the Exploit-DB entry 49703.
Analyst recommendation
Given the availability of a proof-of-concept exploit, this vulnerability should be prioritized for remediation in all environments where ActivIdentity 8.2 is deployed. Administrators must ensure that directory permissions are strictly enforced as an immediate temporary measure while working toward a permanent software update.
Sources
Originally found and disclosed by SamAlucard, per the CVE Program record.
- ExploitDB-49703 Exploit / PoC
- HID Global Official Website
- VulnCheck Advisory: ActivIdentity 8.2 - 'ac.sharedstore' Unquoted Service Path Third-party advisory