A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT AUTHORITY/SYSTEM) allows unprivileged users to run a Microsoft Installer executable with elevated privileges.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2020-06-16 20:15
Updated : 2024-11-21 05:00
NVD link : CVE-2020-13162
Mitre link : CVE-2020-13162
CVE.ORG link : CVE-2020-13162
JSON object : View
Products Affected
pulsesecure
- pulse_secure_installer_service
- pulse_secure_desktop_client
CWE
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition