Attackers Can Execute Arbitrary Code via SonicWall NetExtender Client Update
CVE-2024-29014
Summary
The SonicWall NetExtender client update vulnerability (CVE-2024-29014) allows attackers to execute arbitrary code, while the Palo Alto Networks GlobalProtect App vulnerability (CVE-2024-5921) allows for remote code execution and privilege escalation. These vulnerabilities can be exploited to achieve remote code execution. Both vendors have released patches to address these vulnerabilities. While the exploits have not been exploited by ransomware groups, the potential impact of the vulnerabilities is significant, as attackers could install malicious software and compromise systems. The release of NachoVPN, an open-source tool that simulates rogue VPN servers capable of exploiting these and other vulnerabilities, highlights the urgency of addressing these vulnerabilities.
Affected Version(s)
NetExtender Windows 10.2.339 and earlier versions
News Articles
References
CVSS V3.1
Timeline
- π°
First article discovered by Help Net Security
Vulnerability published
Vulnerability Reserved