First published: Wed May 04 2022(Updated: )
SonicWall Global VPN Client 4.10.7.1117 installer (32-bit and 64-bit) and earlier versions have a DLL Search Order Hijacking vulnerability in one of the installer components. Successful exploitation via a local attacker could result in command execution in the target system.
Credit: PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWALL GLobal VPN Client | <=4.10.7.1117 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20051 is a DLL Search Order Hijacking vulnerability found in SonicWall Global VPN Client version 4.10.7.1117 and earlier.
Successful exploitation of CVE-2021-20051 could allow a local attacker to execute commands on the target system.
CVE-2021-20051 has a severity rating of 7.8 (high).
SonicWall Global VPN Client versions up to and including 4.10.7.1117 are affected by CVE-2021-20051.
Update your SonicWall Global VPN Client to a version beyond 4.10.7.1117 to mitigate the vulnerability.