SonicWALL SSL-VPN Buffer Overflow Vulnerability
RISK: Medium Risk
A vulnerability has been identified in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX Control, which could be exploited by remote attackers to compromise a vulnerable system.
The vulnerability is caused due to a boundary error in the "Aventail.EPInstaller" ActiveX control when handling the "Install3rdPartyComponent()" method. This can be exploited to cause a stack-based buffer overflow via specially crafted "CabURL" and "Location" arguments.
Impact
- Remote Code Execution
System / Technologies affected
- SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX Control 10.x
Solutions
Update to version 10.5.2 and apply hotfix 3 for version 10.0.5.
Vulnerability Identifier
Source
Related Link
Share with