Dell SonicWall netexloud Privilege Escalation Vulnerability (CVE-2015-4173)
Dell SonicWall netexloud Privilege Escalation Vulnerability (CVE-2015-4173)
Release date:
Updated on:
Affected Systems:
SonicWALL NetExtender <8.0.0.3
SonicWALL NetExtender <7.5.1.2
Description:
CVE (CAN) ID: CVE-2015-4173
SonicWALL NetExtender allows remote users to Securely connect to the remote network.
In versions earlier than SonicWALL netex00007.5.1.2 and earlier than 8.0.0.3, The unreferenced Windows Search Path Vulnerability exists in autorun value. Local users use the trojan program in the % SYSTEMDRIVE % folder, you can obtain elevated permissions.
<* Source: Andrew Smith
Link: http://www.securityfocus.com/archive/1/archive/1/536303/100/0/threaded
*>
Suggestion:
Vendor patch:
SonicWALL
---------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.sonicwall.com
This article permanently updates the link address: