First published: Tue Oct 03 2023(Updated: )
A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYSTEM' level privileges, leading to a local privilege escalation (LPE) vulnerability.
Credit: PSIRT@sonicwall.com PSIRT@sonicwall.com
Affected Software | Affected Version | How to fix |
---|---|---|
SonicWall NetExtender Windows | <=10.2.336 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the SonicWall NetExtender Pre-Logon feature flaw is CVE-2023-44218.
The SonicWall NetExtender Pre-Logon feature flaw allows unauthorized users to gain access to the host Windows operating system with 'SYSTEM' level privileges.
The impact of the SonicWall NetExtender Pre-Logon feature flaw is a local privilege escalation (LPE) vulnerability.
The version of SonicWall NetExtender affected by the vulnerability is up to and including 10.2.336.
The SonicWall NetExtender Pre-Logon feature flaw has a severity score of 7.8 (high).