DLL Search Order Hijacking Vulnerability in SonicWall Global VPN Client
CVE-2021-20047

7.8HIGH

Key Information:

Vendor
Sonicwall
Vendor
CVE Published:
8 December 2021

Summary

The SonicWall Global VPN Client versions up to 4.10.6 are susceptible to a DLL Search Order Hijacking vulnerability. This flaw allows a local attacker to exploit the application's improper search path for dynamic link libraries (DLLs), leading to potential remote code execution on the targeted system. Attackers can leverage this weakness to manipulate the execution flow of the application, potentially compromising system integrity.

Affected Version(s)

SonicWall Global VPN Client Global VPN Client 4.10.6 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.