Zyxel security advisory for out-of-bounds write vulnerability in SecuExtender SSL VPN Client software.
Zyxel has released patches for the Windows-based SecuExtender SSL VPN Client software affected by an out-of-bounds write vulnerability. Users are advised to install them for optimal protection.
What is the vulnerability?
The out-of-bounds write vulnerability in the Windows-based SecuExtender SSL VPN Client software could allow a local authenticated user to gain a privilege escalation by sending a crafted CREATE message.
What versions are vulnerable—and what should you do?
After a thorough investigation, we have confirmed that only the Windows-based SecuExtender SSL VPN Client software is affected and have released a patch to address the issue, as shown in the table below.
|SecuExtender SSL VPN Client
|V220.127.116.11 (for Windows)
|V18.104.22.168 (for Windows)
Got a question?
Please contact your local service rep or visit Zyxel’s Community for further information or assistance.
Thanks to Daniele Scanu and Fabio Carretto from Soter IT Security for reporting the issue to us.
2023-11-21: Initial release.