CVE-2025-23007 Details
Description
A vulnerability in the NetExtender Windows client log export function allows unauthorized access to sensitive Windows system files, potentially leading to privilege escalation.
A vulnerability exists in the NetExtender Windows client log export function, allowing unauthorized access to sensitive Windows system files. This access could potentially lead to privilege escalation. The issue is present in NetExtender Windows version 10.3.0, affecting both 32-bit and 64-bit clients. Notably, NetExtender Windows 10.2.x versions and Linux-based NetExtender clients are not affected.
Users can upgrade to NetExtender Windows version 10.3.1 or higher to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 30, 2025CISA-ADP
Assessed Mar 20, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2025-0005 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SonicWall NetExtender | 10.3.0 (semver) |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Apr 17, 2025 | CVE Modified | CISA-ADP |
| Mar 20, 2025 | CVE Modified | CISA-ADP |
| Feb 18, 2025 | CVE Modified | CISA-ADP |
| Jan 30, 2025 | CVE Modified | CISA-ADP |
| Jan 30, 2025 | New CVE Received | [email protected] |
Volerion