Skip to main content

SonicWall Patches High-Severity Vulnerability in NetExtender


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

SonicWall has released fixes for three vulnerabilities in NetExtender for Windows, including a high-severity bug.

 

April 11, 2025 By Ionut Arghire

 

SonicWall this week announced patches for three vulnerabilities in NetExtender for Windows, including a high-severity security bug.

A VPN client that relies on the SSL protocol for secure communication, NetExtender enables remote users to connect to an enterprise’s network and access resources the same as when connected from the local network.

Tracked as CVE-2025-23008 (CVSS score of 7.2), the high-severity flaw addressed in the latest release of the NetExtender Windows client is described as an improper privilege management bug that could be exploited by authenticated attackers to modify the application’s configuration.

The issue impacts both 32-bit and 64-bit iterations of the client and was addressed with the release of NetExtender Windows version 10.3.2.

The update also resolves two medium-severity vulnerabilities that could allow attackers to manipulate file paths (CVE-2025-23010) or trigger an arbitrary file deletion (CVE-2025-23009).

 

>>Full Article<<

0 replies

Be the first to reply!