8.8
CWE
267
Advisory Published
Updated

CVE-2023-44218

First published: Tue Oct 03 2023(Updated: )

A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYSTEM' level privileges, leading to a local privilege escalation (LPE) vulnerability.

Credit: PSIRT@sonicwall.com PSIRT@sonicwall.com

Affected SoftwareAffected VersionHow to fix
SonicWall NetExtender Windows<=10.2.336

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the vulnerability ID for the SonicWall NetExtender Pre-Logon feature flaw?

    The vulnerability ID for the SonicWall NetExtender Pre-Logon feature flaw is CVE-2023-44218.

  • What does the SonicWall NetExtender Pre-Logon feature flaw allow unauthorized users to do?

    The SonicWall NetExtender Pre-Logon feature flaw allows unauthorized users to gain access to the host Windows operating system with 'SYSTEM' level privileges.

  • What is the impact of the SonicWall NetExtender Pre-Logon feature flaw?

    The impact of the SonicWall NetExtender Pre-Logon feature flaw is a local privilege escalation (LPE) vulnerability.

  • Which version of SonicWall NetExtender is affected by the vulnerability?

    The version of SonicWall NetExtender affected by the vulnerability is up to and including 10.2.336.

  • How severe is the SonicWall NetExtender Pre-Logon feature flaw?

    The SonicWall NetExtender Pre-Logon feature flaw has a severity score of 7.8 (high).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203