DSA-2019-107: Dell Encryption Enterprise and Dell Endpoint Security Suite Enterprise Installer Uncontrolled Search Path Vulnerability

요약: Dell Data Security platforms require an update to address an uncontrolled search path vulnerability that can be exploited during the installation of the product.

이 문서는 다음에 적용됩니다. 이 문서는 다음에 적용되지 않습니다. 이 문서는 특정 제품과 관련이 없습니다. 모든 제품 버전이 이 문서에 나와 있는 것은 아닙니다.

영향

Medium

세부 정보

Uncontrolled Search Path Vulnerability (CVE-2019-3745)
CVSS Base Score: 6.7 (AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)

The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite Enterprise versions prior to 2.4.0. This issue is exploitable only during the installation of the product by an administrator. A local authenticated low privileged user potentially could exploit this vulnerability by staging a malicious DLL in the search path of the installer prior to its execution by a local administrator. This would cause loading of the malicious DLL, which would allow the attacker to execute arbitrary code in the context of an administrator.

 

Uncontrolled Search Path Vulnerability (CVE-2019-3745)
CVSS Base Score: 6.7 (AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H)

The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite Enterprise versions prior to 2.4.0. This issue is exploitable only during the installation of the product by an administrator. A local authenticated low privileged user potentially could exploit this vulnerability by staging a malicious DLL in the search path of the installer prior to its execution by a local administrator. This would cause loading of the malicious DLL, which would allow the attacker to execute arbitrary code in the context of an administrator.

 

Dell Technologies는 모든 고객이 CVSS 기본 점수와 관련 임시 및 환경 점수를 모두 고려할 것을 권장합니다. 이 경우 특정 보안 취약성과 관련된 잠재적인 심각도에 영향을 미칠 수 있습니다.

영향을 받는 제품 및 문제 해결

Affected products:

Dell Encryption Enterprise prior to 10.4.0

Dell Endpoint Security Suite Enterprise prior to 2.4.0
 

Remediation:

The following Dell Data Security releases contains a resolution to this vulnerability:

 

Dell Encryption version 10.4.0 or later

Dell Endpoint Security Suite Enterprise 2.4.0 or later

 

Customers should use the latest version from Dell. Dell recommends installing the latest version of Dell Encryption to receive all of the latest security updates to the product.

 

Browse to the Dell Encryption Software download page for the latest version.

 

Dell Endpoint Security Suite Enterprise software will be made available to customers on their ddpe.credant.com accounts or can be obtained through Dell ProSupport.

Affected products:

Dell Encryption Enterprise prior to 10.4.0

Dell Endpoint Security Suite Enterprise prior to 2.4.0
 

Remediation:

The following Dell Data Security releases contains a resolution to this vulnerability:

 

Dell Encryption version 10.4.0 or later

Dell Endpoint Security Suite Enterprise 2.4.0 or later

 

Customers should use the latest version from Dell. Dell recommends installing the latest version of Dell Encryption to receive all of the latest security updates to the product.

 

Browse to the Dell Encryption Software download page for the latest version.

 

Dell Endpoint Security Suite Enterprise software will be made available to customers on their ddpe.credant.com accounts or can be obtained through Dell ProSupport.

감사의 말

Dell would like to thank Eran Shimony for reporting this vulnerability.

관련 정보

제품

Dell Encryption, Dell Endpoint Security Suite Enterprise
문서 속성
문서 번호: 000138061
문서 유형: Dell Security Advisory
마지막 수정 시간: 18 8월 2025
다른 Dell 사용자에게 질문에 대한 답변 찾기
지원 서비스
디바이스에 지원 서비스가 적용되는지 확인하십시오.