CVE Vulnerabilities

CVE-2023-44218

Privilege Defined With Unsafe Actions

Published: Oct 03, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with SYSTEM level privileges, leading to a local privilege escalation (LPE) vulnerability.

Weakness

A particular privilege, role, capability, or right can be used to perform unsafe actions that were not intended, even when it is assigned to the correct entity.

Affected Software

Name Vendor Start Version End Version
Netextender Sonicwall * 10.2.336 (including)

Potential Mitigations

References