ID:8702 - Exploit for Absolute Path Traversal in SonicWall Capture Client and SentinelOne Agent for Windows

 
Main Vulnerability Database Exploits ID:8702 - Exploit for Absolute Path Traversal in SonicWall Capture Client and SentinelOne Agent for Windows

ID:8702 - Exploit for Absolute Path Traversal in SonicWall Capture Client and SentinelOne Agent for Windows

Published: December 28, 2022


Vulnerability identifier: #VU70521
Vulnerability risk: Low
CVE-ID: N/A
CWE-ID: CWE-36
Exploitation vector: Local access
Vulnerable software:
SonicWall Capture Client
SentinelOne Agent for Windows

Link to public exploit:


Vulnerability description

The vulnerability allows a local user to delete arbitrary files on the system.

The vulnerability exists due to insecure file path processing in Sonicwall Capture Client. A local user can delete arbitrary system files and escalate privileges.


Remediation

Install updates from vendor's website.