CVE Vulnerabilities

CVE-2020-8239

Published: Oct 28, 2020 | Modified: Aug 17, 2021
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires Server Side Upgrade due to Standalone Host Checker Client (Windows) and Windows PDC.

Affected Software

Name Vendor Start Version End Version
Pulse_secure_desktop_client Pulsesecure * 9.1 (excluding)
Pulse_secure_desktop_client Pulsesecure 9.1-r1 (including) 9.1-r1 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r2 (including) 9.1-r2 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r3 (including) 9.1-r3 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r3.1 (including) 9.1-r3.1 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r4 (including) 9.1-r4 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r4.1 (including) 9.1-r4.1 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r4.2 (including) 9.1-r4.2 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r5 (including) 9.1-r5 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r6 (including) 9.1-r6 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r7 (including) 9.1-r7 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r7.1 (including) 9.1-r7.1 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r8 (including) 9.1-r8 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r8.2 (including) 9.1-r8.2 (including)

References