Privilege Escalation Vulnerability in SonicWall Global VPN Client
CVE-2020-5144
7.8HIGH
Key Information:
- Vendor
- Sonicwall
- Vendor
- CVE Published:
- 28 October 2020
Summary
The SonicWall Global VPN Client contains a vulnerability that allows unprivileged Windows users to gain elevated privileges to the SYSTEM level. This security flaw is attributed to a loaded process hijacking, which can be exploited by attackers to execute malicious code with higher privileges than intended. Users are advised to update to the latest version to mitigate this vulnerability.
Affected Version(s)
SonicWall Global VPN Client 4.10.4.0314 and earlier
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved