Skip to main content

Security Notice: SonicWall Global VPN Client DLL Search Order Hijacking via Application Installer

  • April 28, 2022
  • 11 replies
  • 50 views

kleinmat4103
Popular Voice
Forum|alt.badge.img+6

Path-41173.pngFirst Published:04/27/2022Group-9067.pngLast Updated:04/28/2022


SonicWall has confirmed that Global VPN Client (GVC) installer 4.10.7.1117 (32-bit and 64-bit) and earlier versions have three specific vulnerabilities in one of the installer components as outlined below:

  1. Global VPN Client DLL Search Order Hijacking via Application Installer (RunMSI.exe). This includes both the 32-Bit as well as 64-bit installers.
     
  2. Global VPN Client Installer being unable to remove RarSFX folder and its content after installation. Therefore, all organizations and/or users who have installed the latest GVC version have the problematic RarSFX folder and its vulnerable component (RunMSI.exe), which could lead to potential exploitation of the first vulnerability above. Only the last three 64-bit versions 4.10.7.1117, 4.10.6.0913 and 4.10.5.1224 are impacted.
     
  3. 32-Bit Global VPN Client DLL Highjacking over Microsoft Foundation Class DLLs. While first two vulnerabilities apply to the installer, this one is in the application itself. Only the 32-bit version of GVC is vulnerable. 

<< Full Article >>

11 replies

kleinmat4103
Popular Voice
Forum|alt.badge.img+6
  • Author
  • Popular Voice
  • April 28, 2022

If you or any of your clients use Sonicwall Global VPN Client, would be a good time to make sure they are not using an vulnerable version of the installer.

 

Stay safe out there!


MajorHavoc
Bronze VIP
Forum|alt.badge.img+25
  • Bronze VIP
  • April 28, 2022

I hate to admit it but I pulled Sonicwall devices out of most locations. They were too expensive, and small issues kept creeping in. Did not feel they lived up to the reputation they had 20 years ago.  But would be curious to what people here recommend for SMSO edge devices at a reasonable price for small organizations?  What are you all recommending?


kleinmat4103
Popular Voice
Forum|alt.badge.img+6
  • Author
  • Popular Voice
  • April 28, 2022

We are still a Sonicwall shop and have had good success with them. They definitely took a downturn when Dell bought them, but they bounced back pretty well after they got back on their own. Their TZ series is what we typically recommend to most SMBs.

 

I am also curious what edge devices people are using.


stlshark
New Member
Forum|alt.badge.img+1
  • New Member
  • April 28, 2022

I appreciate you taking the time to share this. Though we do not use Sonicwall ourselves, a good friend of mine works for a company who does have a few to support. Forwarded on to him. 

 

We are using Fortinet firewalls internally and they have worked well. In my area there has been a big push recently for Cisco Meraki. 


kleinmat4103
Popular Voice
Forum|alt.badge.img+6
  • Author
  • Popular Voice
  • April 28, 2022

No problem, @stlshark . Thanks for sharing!

We know a lot of others using Fortinet. Our biggest complaint with SW is the lack of a central management portal. Well, the lack of one that isn’t absurdly expensive, at least. Does Fortinet have any kind of centralized management portal?

We have a few clients on Meraki, and we like them. But they are expensive!


stlshark
New Member
Forum|alt.badge.img+1
  • New Member
  • April 28, 2022

No problem, @stlshark . Thanks for sharing!

We know a lot of others using Fortinet. Our biggest complaint with SW is the lack of a central management portal. Well, the lack of one that isn’t absurdly expensive, at least. Does Fortinet have any kind of centralized management portal?

We have a few clients on Meraki, and we like them. But they are expensive!

We are only using them internally, but they do have Forticloud which allows you to manage all of your devices from one place. Overall their ecosystem is pretty nice, but I think Meraki is still the better option overall. 


MajorHavoc
Bronze VIP
Forum|alt.badge.img+25
  • Bronze VIP
  • April 28, 2022

We are still a Sonicwall shop and have had good success with them. They definitely took a downturn when Dell bought them, but they bounced back pretty well after they got back on their own. Their TZ series is what we typically recommend to most SMBs.

 

I am also curious what edge devices people are using.

Thanks. I have not used them since Dell bought them and have not followed them since, so was no aware that they were back on their own.  I will check them out again.  Appreciate the comment. 


MunkeyMan
New Voice
Forum|alt.badge.img+4
  • New Voice
  • May 1, 2022

Thanks for sharing. I do value these comments and articles they are great for information sharing. We aren’t a Somicwall house but useful to know in case of any legacy clients still with kit outside of our standard stack. 


Jamesharris85
New Voice
Forum|alt.badge.img+4

Not a SonicWall house but have a couple of clients using their kit but we are actively trying to steer them to a different product, the knowledge required for properly and securely managing them seems to be a bit rare and the cost to boot is too much in most cases


Forum|alt.badge.img+8
  • New Voice
  • May 1, 2022

We were SonicWall at my old MSP but moved of to Sophos years ago. there was a lot I liked and the VPN was one of them


Jamesharris85
New Voice
Forum|alt.badge.img+4

The sophos VPN or the sonicwall one?