Home / exploitsPDF  

Pulse Secure VPN Remote Code Execution

Posted on 19 December 2020

The Pulse Connect Secure appliance versions prior to 9.1R9 suffer from an uncontrolled gzip extraction vulnerability which allows an attacker to overwrite arbitrary files, resulting in remote code execution as root. Admin credentials are required for successful exploitation.

 

TOP