PT-2024-31568 · Sonicwall · Sonicwall Connect Tunnel

Hashim Jawad

·

Published

2024-10-10

·

Updated

2024-10-16

·

CVE-2024-45316

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SonicWall Connect Tunnel versions 12.4.3.271 and earlier of Windows client
Description The issue allows users with standard privileges to delete arbitrary folders and files, potentially leading to a local privilege escalation attack. This is due to improper link resolution before file access, also known as 'Link Following'.
Recommendations For SonicWall Connect Tunnel versions 12.4.3.271 and earlier of Windows client, update to a version later than 12.4.3.271 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files and folders to minimize the risk of exploitation.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-45316
ZDI-24-1334

Affected Products

Sonicwall Connect Tunnel