Privilege Escalation Vulnerability in SonicWall Global VPN Client
CVE-2020-5144

7.8HIGH

Key Information:

Vendor
Sonicwall
Vendor
CVE Published:
28 October 2020

Summary

The SonicWall Global VPN Client contains a vulnerability that allows unprivileged Windows users to gain elevated privileges to the SYSTEM level. This security flaw is attributed to a loaded process hijacking, which can be exploited by attackers to execute malicious code with higher privileges than intended. Users are advised to update to the latest version to mitigate this vulnerability.

Affected Version(s)

SonicWall Global VPN Client 4.10.4.0314 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.