Arbitrary File Write Vulnerability in SonicWall NetExtender for Windows
CVE-2020-5131
7.8HIGH
Summary
The SonicWall NetExtender Windows client is susceptible to an arbitrary file write vulnerability that allows an attacker to overwrite a DLL file. If exploited, this weakness enables the execution of malicious code with the same privileges as the host operating system. This potentially severe flaw impacts all versions of the SonicWall NetExtender Windows client up to and including version 9.0.815, posing significant security risks for users.
Affected Version(s)
SonicWall NetExtender 9.0.815 and earlier
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved