QID 379004

Date Published: 2023-11-28

QID 379004: SonicWall NetExtender Windows Client Search Order Hijacking Vulnerability (SNWLID-2023-0017)

SonicWALL NetExtender is a software application that enables remote users to securely connect to the remote network.

SonicWall NetExtender Windows (32 and 64-bit) client 10.2.336 and earlier versions have a Dynamic link library (DLL) Search Order Hijacking vulnerability in the start-up DLL component. Successful exploitation via a local attacker could result in command execution in the target system.

Affected Product versions:
NetExtender 10.2.336 and earlier versions.
QID Detection Logic:
This QID detects the vulnerable version from the SonicWall NetExtender Executable.

Upon successful exploitation via a local attacker could result in command execution in the target system.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Vendor has released patch. For more details, please refer to SNWLID-2023-0017
    Vendor References

    CVEs related to QID 379004

    Software Advisories
    Advisory ID Software Component Link
    SNWLID-2023-0017 URL Logo psirt.global.sonicwall.com/vuln-detail/SNWLID-2023-0017