DSA-2024-263: Security Update for Dell Command| Update, Dell Update, Alienware Update, and Dell SupportAssist for a Path Traversal Vulnerability
Summary: Dell released remediation for a Path Traversal vulnerability in Dell Inventory Collector invoked within Dell Command| Update, Dell Update, Dell Alienware Update, and Dell SupportAssist for PCs (Home and Business) ...
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
Medium
Details
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2024-37129 | Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system. | 6.7 | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
| CVE-2024-37129 | Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system. | 6.7 | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Affected Products & Remediation
| Product | Affected Versions | Remediated Versions | Release date (MM/DD/YYYY) | Link |
|---|---|---|---|---|
| Dell Inventory Collector | Versions prior to 12.3.0.6 | Versions 12.3.0.6 and later | 06/24/2024 | Drivers and Download FAQs |
| Product | Affected Versions | Remediated Versions | Release date (MM/DD/YYYY) | Link |
|---|---|---|---|---|
| Dell Inventory Collector | Versions prior to 12.3.0.6 | Versions 12.3.0.6 and later | 06/24/2024 | Drivers and Download FAQs |
Dell Command Update, Dell Update, Alienware Update, and Dell SupportAssist for PCs (Home and Business) automatically updates Inventory Collector without any user interaction. To verify if you are running the remediated version, follow below steps:
- Goto C:\Program Files (x86)\Dell\UpdateService\Service\InvColPC\
- Right Click on invcol.exe, click on Properties, then go to Details tab.
- Verify Product Version is 12.3.0.6 or later.
- If version is not 12.3.0.6 or later,
- Windows Search and select SupportAssist
- Open SupportAssist
- Navigate to “Get Drivers and Downloads” and click on “Run Now”.
- Windows Search and select Dell Command| Update/ Dell Update/ Alienware Update
- Open Dell Command| Update/ Dell Update/ Alienware Update
- Click on “Check”.
Workarounds & Mitigations
None
Revision History
| Revision | Date | Description |
| 1.0 | 2024-07-30 | Initial Release |
| 2.0 | 2024-07-31 | Added Revision History Table |
Acknowledgements
CVE-2024-37129: Dell Technologies would like to thank Jony_Juice for reporting this issue.
Related Information
Legal Disclaimer
Affected Products
Alienware Update, SupportAssist, Dell Command | Update, Dell UpdateArticle Properties
Article Number: 000225779
Article Type: Dell Security Advisory
Last Modified: 31 Jul 2024
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.