CVE Vulnerabilities

CVE-2020-8240

Published: Oct 28, 2020 | Modified: Nov 03, 2020
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured with Credential Provider. This vulnerability only affects Windows PDC if the Embedded Browser is configured with the Credential Provider.

Affected Software

Name Vendor Start Version End Version
Pulse_secure_desktop_client Pulsesecure * 9.1 (excluding)
Pulse_secure_desktop_client Pulsesecure 9.1-r1 (including) 9.1-r1 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r2 (including) 9.1-r2 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r3 (including) 9.1-r3 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r3.1 (including) 9.1-r3.1 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r4 (including) 9.1-r4 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r4.1 (including) 9.1-r4.1 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r4.2 (including) 9.1-r4.2 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r5 (including) 9.1-r5 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r6 (including) 9.1-r6 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r7 (including) 9.1-r7 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r7.1 (including) 9.1-r7.1 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r8 (including) 9.1-r8 (including)
Pulse_secure_desktop_client Pulsesecure 9.1-r8.2 (including) 9.1-r8.2 (including)

References