Privilege Escalation in SonicWall Global VPN Client by Incorrect File Permissions
CVE-2021-20037
7.8HIGH
Key Information:
- Vendor
Sonicwall
- Vendor
- CVE Published:
- 21 September 2021
What is CVE-2021-20037?
The SonicWall Global VPN Client installer versions 4.10.5 and earlier suffer from an issue due to incorrect default file permissions. This vulnerability allows local users to escalate privileges, granting them the capability to execute commands with elevated permissions on the host operating system, potentially compromising system integrity. Organizations using affected versions should consider immediate action to mitigate risks.
Affected Version(s)
SonicWall Global VPN Client Global VPN Client 4.10.5 and earlier