CVE-2020-13162: High severity pulsesecure pulse secure desktop client vulnerability
A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT AUTHORITY/SYSTEM) allows unprivileged users to run a Microsoft Installer executable with elevated privileges.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-13162?
CVE-2020-13162 is a time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows.
What is the severity of CVE-2020-13162?
The severity of CVE-2020-13162 is high, with a severity value of 7.
How does CVE-2020-13162 affect Pulse Secure Desktop Client?
CVE-2020-13162 affects Pulse Secure Desktop Client versions 5.3 R1.0 to 5.3 R70 for Windows.
How does CVE-2020-13162 allow privilege escalation?
CVE-2020-13162 allows unprivileged users to run a Microsoft Installer executable with elevated privileges.
Are there any known fixes for CVE-2020-13162?
Yes, the fix for CVE-2020-13162 is to upgrade to Pulse Secure Client version 9.1.6 or later.