PT-2020-20051 · Pulse Secure · Pulse Secure Desktop Client
Published
2020-10-28
·
Updated
2020-11-03
·
CVE-2020-8240
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Pulse Secure Desktop Client versions prior to 9.1R9
Description
A vulnerability allows a restricted user on an endpoint machine to use system-level privileges if the Embedded Browser is configured with Credential Provider. This issue only affects Windows Pulse Secure Desktop Client when the Embedded Browser is set up with the Credential Provider.
Recommendations
For Pulse Secure Desktop Client versions prior to 9.1R9, update to version 9.1R9 or later to resolve the issue.
As a temporary workaround, consider disabling the Embedded Browser's Credential Provider configuration until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pulse Secure Desktop Client