Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-whvw-59jf-hrx9

Опубликовано: 06 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.7

Описание

Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in installed directory and taking reverse shell of the system leading to Privilege Escalation.

Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in installed directory and taking reverse shell of the system leading to Privilege Escalation.

EPSS

Процентиль: 13%
0.00043
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.7
nvd
около 2 лет назад

Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in installed directory and taking reverse shell of the system leading to Privilege Escalation.

CVSS3: 6.7
fstec
около 2 лет назад

Уязвимость программного средства защиты конечных точек Encryption, программного средства предотвращения, обнаружения угроз безопасности информации Dell Endpoint Security Suite Enterprise и сервера управления безопасностью Dell Security Management Server, связанная с недостатками контроля доступа, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 13%
0.00043
Низкий

6.7 Medium

CVSS3

Дефекты

CWE-284