PT-2020-5945 · Pulse Secure · Pulse Secure Client

Published

2020-06-16

·

Updated

2025-05-05

·

CVE-2020-13162

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Pulse Secure Client versions prior to 9.1.6
Description: A time-of-check time-of-use vulnerability in PulseSecureService.exe allows unprivileged users to run a Microsoft Installer executable with elevated privileges. This issue is caused by a "race condition" situation, which can be exploited by an attacker to elevate their privileges.
Recommendations: For Pulse Secure Client versions prior to 9.1.6, update to version 9.1.6 or later to resolve the issue. As a temporary workaround, consider restricting access to the PulseSecureService.exe to minimize the risk of exploitation.

Exploit

Fix

Time Of Check To Time Of Use

Weakness Enumeration

Related Identifiers

BDU:2021-02075
CVE-2020-13162

Affected Products

Pulse Secure Client