SonicWall PSIRT has worked with engineering and product teams to confirm and correct three vulnerabilities associated with the SonicWall Global VPN Client (GVC), two of which impact the included client installer. Successful exploitation via a privileged user could potentially result in command execution in the target system.
IMPORTANT: There is no evidence that these vulnerabilities are being exploited in the wild. The three vulnerabilities can only be exploited after the adversary gains control of the machine, has admin privilege or is able to place malicious files on the machine.
SonicWall strongly urges that organizations using 32- and 64-bit GVC versions in their networks carefully review the knowledge base (KB) article and follow guidance for upgrade.
Notes: There are different mitigation steps for 32- and 64-bit GVC versions. Please read the KB article carefully to resolve issues to your specific version.