Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-52535

Опубликовано: 25 дек. 2024
Источник: nvd
CVSS3: 7.1
CVSS3: 8.8
EPSS Низкий

Описание

Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dell:supportassist_for_business_pcs:*:*:*:*:*:*:*:*
Версия до 4.5.1 (исключая)
cpe:2.3:a:dell:supportassist_for_home_pcs:*:*:*:*:*:*:*:*
Версия до 4.6.2 (исключая)

EPSS

Процентиль: 30%
0.00109
Низкий

7.1 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-61
CWE-59

Связанные уязвимости

CVSS3: 7.1
github
8 месяцев назад

Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.

EPSS

Процентиль: 30%
0.00109
Низкий

7.1 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-61
CWE-59