Absolute Path Traversal in SonicWall Capture Client and SentinelOne Agent for Windows - #VU70521
Published: December 28, 2022 / Updated: December 28, 2022
Vulnerability identifier: #VU70521
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-36
Exploitation vector: Local access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a local user to delete arbitrary files on the system.
The
vulnerability exists due to insecure file path processing in Sonicwall
Capture Client. A local user can delete arbitrary system files and
escalate privileges.
Affected software
SonicWall Capture Client
SentinelOne Agent for Windows
SentinelOne Agent for Windows
Remediation
Install updates from vendor's website.
SentinelOne Agent for Windows - update to 22.2.3.402