Main
Vulnerability Database
Exploits
ID:8702 - Exploit for Absolute Path Traversal in SonicWall Capture Client and SentinelOne Agent for Windows
ID:8702 - Exploit for Absolute Path Traversal in SonicWall Capture Client and SentinelOne Agent for Windows
Published: December 28, 2022
Vulnerability identifier: #VU70521
Vulnerability risk: Low
CVE-ID: N/A
CWE-ID: CWE-36
Exploitation vector: Local access
Vulnerable software:
SonicWall Capture Client
SentinelOne Agent for Windows
SonicWall Capture Client
SentinelOne Agent for Windows
Link to public exploit:
Vulnerability description
The vulnerability allows a local user to delete arbitrary files on the system.
The
vulnerability exists due to insecure file path processing in Sonicwall
Capture Client. A local user can delete arbitrary system files and
escalate privileges.
Remediation
Install updates from vendor's website.