CVE-2024-45316

HIGH

SonicWall Connect Tunnel <12.4.3.271 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to delete arbitrary folders and files, potentially leading to local privilege escalation attack.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0006
EPSS Percentile 17.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-59
Status published
Products (1)
SonicWall/Connect Tunnel 12.4.3.271 and earlier versions
Published Oct 11, 2024
Tracked Since Feb 18, 2026