SonicWall Global VPN client version 4.10.6 (32-bit and 64-bit) and earlier have a DLL Search Order Hijacking vulnerability. Successful exploitation via a local attacker could result in remote code execution in the target system.
References
Link | Resource |
---|---|
https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2021-0025 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-12-08 02:15
Updated : 2021-12-10 07:16
NVD link : CVE-2021-20047
Mitre link : CVE-2021-20047
JSON object : View
CWE
CWE-427
Uncontrolled Search Path Element
Products Affected
sonicwall
- global_vpn_client