Centrify develops identity and access management software spanning authentication services, deployment management, and directory control products that integrate with enterprise infrastructure. The observed vulnerability signal centers on deserialization of untrusted data and improper link resolution, reflecting the complexity of credential handling and file-access logic in middleware-layer authentication systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Centrify over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-18631HIGH The Windows component of Centrify Authentication and Privilege Elevation Services 3.4.0, 3.4.1, 3.4.2, 3.4.3, 3.5.0, 3.5.1 (18.8), 3.5.2 (18.11), and 3.6.0 (19.6) does not properly | Nov 5, 2019 | 7.8 | 25 | NO | NO |
Centrify Deployment Manager 2.1.0.283, as distributed in Centrify Suite before 2012.5, allows local users to (1) overwrite arbitrary files via a symlink attack on the adcheckDMoutp | Jan 4, 2013 | 3.3 | 16 | NO | NO |
CVE-2014-7298MEDIUM adsetgroups in Centrify Server Suite 2008 through 2014.1 and Centrify DirectControl 3.x through 4.2.0 on Linux and UNIX allows local users to read arbitrary files with root privile | Oct 24, 2014 | 4.9 | 15 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Centrify.
Media articles that mention a CVE ID that affects a product developed by Centrify — matched by CVE ID, not by vendor name.