DSA-2020-058: Dell/Alienware Digital Delivery Security Update for an Incorrect Default Permissions Vulnerability
Zusammenfassung: Dell Digital Delivery versions prior to 3.5.2015 contain an incorrect default permissions vulnerability.
Auswirkungen
High
Details
-
- Incorrect Default Permissions Vulnerability
Dell Digital Delivery versions prior to 3.5.2015 contain an incorrect default permissions vulnerability. A locally authenticated low-privileged malicious user could exploit this vulnerability to run an arbitrary executable with administrative privileges on the affected system.
7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Incorrect Default Permissions Vulnerability
Dell Digital Delivery versions prior to 3.5.2015 contain an incorrect default permissions vulnerability. A locally authenticated low-privileged malicious user could exploit this vulnerability to run an arbitrary executable with administrative privileges on the affected system.
7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Betroffene Produkte und Korrektur
Affected products:
Dell Digital Delivery versions prior to 3.5.2015
Alienware Digital Delivery versions prior to 3.5.2015
Remediation:
The following Dell/Alienware Digital Delivery releases contain a resolution to these vulnerabilities:
- Dell Digital Delivery versions 3.5.2015 and later
- Alienware Digital Delivery versions 3.5.2015 and later
Dell recommends all customers upgrade at the earliest opportunity.
Please visit the Dell Support Drivers and Downloads site for updates on the applicable products.
Affected products:
Dell Digital Delivery versions prior to 3.5.2015
Alienware Digital Delivery versions prior to 3.5.2015
Remediation:
The following Dell/Alienware Digital Delivery releases contain a resolution to these vulnerabilities:
- Dell Digital Delivery versions 3.5.2015 and later
- Alienware Digital Delivery versions 3.5.2015 and later
Dell recommends all customers upgrade at the earliest opportunity.
Please visit the Dell Support Drivers and Downloads site for updates on the applicable products.
Workarounds und Korrekturmaßnahmen
None
Danksagung
Dell would like to thank Nuttakorn Tungpoonsup of Secure D Center Research Team, Secure D Center Co.,Ltd., Ammarit Thongthua of Secure D Center Research Team, Secure D Center Co.,Ltd., and Sittikorn Sangrattanapitak for reporting this vulnerability.