DLL Search Order Hijacking Vulnerability in SonicWall Global VPN Client
CVE-2021-20047
7.8HIGH
Key Information:
- Vendor
- Sonicwall
- Vendor
- CVE Published:
- 8 December 2021
Summary
The SonicWall Global VPN Client versions up to 4.10.6 are susceptible to a DLL Search Order Hijacking vulnerability. This flaw allows a local attacker to exploit the application's improper search path for dynamic link libraries (DLLs), leading to potential remote code execution on the targeted system. Attackers can leverage this weakness to manipulate the execution flow of the application, potentially compromising system integrity.
Affected Version(s)
SonicWall Global VPN Client Global VPN Client 4.10.6 and earlier
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved