Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xvw3-fvp9-cwjw

Опубликовано: 25 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.

Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.

EPSS

Процентиль: 30%
0.00109
Низкий

7.1 High

CVSS3

Дефекты

CWE-59
CWE-61

Связанные уязвимости

CVSS3: 7.1
nvd
8 месяцев назад

Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.

EPSS

Процентиль: 30%
0.00109
Низкий

7.1 High

CVSS3

Дефекты

CWE-59
CWE-61