CVE-2015-4173

Dell SonicWall NetExtender <8.0.238 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Unquoted Windows search path vulnerability in the autorun value in Dell SonicWall NetExtender before 7.5.227 and 8.0.x before 8.0.238, as used in the SRA firmware before 7.5.1.2-40sv and 8.x before 8.0.0.3-23sv, allows local users to gain privileges via a Trojan horse program in the %SYSTEMDRIVE% folder.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/536303/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1033417

Scores

EPSS 0.0034
EPSS Percentile 56.7%

Details

CWE
CWE-428
Status published
Products (1)
sonicwall/netextender < 7.5.227
Published Aug 26, 2015
Tracked Since Feb 18, 2026