Vulnerabilities > Pulsesecure > Pulse Secure Desktop > High

DATE CVE VULNERABILITY TITLE RISK
2018-09-12 CVE-2018-7572 Improper Authentication vulnerability in Pulsesecure Pulse Secure Desktop
Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can allow attackers to bypass Windows authentication and execute commands on the system with the privileges of Pulse Secure Client.
local
low complexity
pulsesecure CWE-287
7.2
2016-08-02 CVE-2016-2408 Permissions, Privileges, and Access Controls vulnerability in Pulsesecure products
Pulse Secure Desktop before 5.2R2 and Pulse Secure Installer Service before 8.2R2 and below for Windows allow restricted users to gain privileges via unspecified vectors.
local
low complexity
pulsesecure CWE-264
7.2