CVE-2024-45316
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Oct 11, 2024
Updated: Oct 15, 2024
CWE ID 59
Summary
CVE-2024-45316 is a vulnerability affecting SonicWall Connect Tunnel's Windows client (version 12.4.3.271 and earlier). This issue involves improper link resolution before file access, also known as 'Link Following'. An attacker with standard privileges can exploit this vulnerability to delete arbitrary folders and files, increasing the risk of local privilege escalation attacks. This can potentially give malicious actors considerable control over the affected system. Users are advised to update their SonicWall Connect Tunnel software to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.