A time-of-check time-of-use vulnerability in...
Moderate severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Mar 9, 2023
Description
Published by the National Vulnerability Database
Jun 16, 2020
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Mar 9, 2023
A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT AUTHORITY/SYSTEM) allows unprivileged users to run a Microsoft Installer executable with elevated privileges.
References