Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-36286

Опубликовано: 28 сент. 2021
Источник: nvd
CVSS3: 7.1
CVSS2: 3.6
EPSS Низкий

Описание

Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability that can be exploited by using the Windows feature of NTFS called Symbolic links. Symbolic links can be created by any(non-privileged) user under some object directories, but by themselves are not sufficient to successfully escalate privileges. However, combining them with a different object, such as the NTFS junction point allows for the exploitation. Support assist clean files functionality do not distinguish junction points from the physical folder and proceeds to clean the target of the junction that allows nonprivileged users to create junction points and delete arbitrary files on the system which can be accessed only by the admin.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:dell:supportassist_client_consumer:*:*:*:*:*:*:*:*
Версия до 3.9.13.0 (включая)

EPSS

Процентиль: 20%
0.00065
Низкий

7.1 High

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-22
CWE-59

Связанные уязвимости

CVSS3: 7.1
github
больше 3 лет назад

Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability that can be exploited by using the Windows feature of NTFS called Symbolic links. Symbolic links can be created by any(non-privileged) user under some object directories, but by themselves are not sufficient to successfully escalate privileges. However, combining them with a different object, such as the NTFS junction point allows for the exploitation. Support assist clean files functionality do not distinguish junction points from the physical folder and proceeds to clean the target of the junction that allows nonprivileged users to create junction points and delete arbitrary files on the system which can be accessed only by the admin.

EPSS

Процентиль: 20%
0.00065
Низкий

7.1 High

CVSS3

3.6 Low

CVSS2

Дефекты

CWE-22
CWE-59