CVE Vulnerabilities

CVE-2020-8239

Published: Oct 28, 2020 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires Server Side Upgrade due to Standalone Host Checker Client (Windows) and Windows PDC.

Affected Software

NameVendorStart VersionEnd Version
Pulse_secure_desktop_clientPulsesecure*9.1 (excluding)
Pulse_secure_desktop_clientPulsesecure9.1-r1 (including)9.1-r1 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r2 (including)9.1-r2 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r3 (including)9.1-r3 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r3.1 (including)9.1-r3.1 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r4 (including)9.1-r4 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r4.1 (including)9.1-r4.1 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r4.2 (including)9.1-r4.2 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r5 (including)9.1-r5 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r6 (including)9.1-r6 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r7 (including)9.1-r7 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r7.1 (including)9.1-r7.1 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r8 (including)9.1-r8 (including)
Pulse_secure_desktop_clientPulsesecure9.1-r8.2 (including)9.1-r8.2 (including)

References