CVE-2023-44218: SonicWall Netextender

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A flaw within the SonicWall NetExtender Pre-Logon feature enables an unauthorized user to gain access to the host Windows operating system with 'SYSTEM' level privileges, leading to a local privilege escalation (LPE) vulnerability.

Affected products

  • SonicWall Netextender: up to and including 10.2.336

Published 2023-10-03. Last modified 2026-06-17.