CVE-2020-13162: Pulse Secure Desktop Client
High severity, CVSS 7.0. EPSS: 0.8% chance of exploitation in the next 30 days.
A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT AUTHORITY/SYSTEM) allows unprivileged users to run a Microsoft Installer executable with elevated privileges.
Affected products
- Pulse Secure Pulse Secure Desktop Client: version 5.3 only; version 9.0 only; version 9.1 only
- Pulse Secure Pulse Secure Installer Service: version 8.3 only; version 9.1 only
Published 2020-06-16. Last modified 2026-06-17.