DSA-2024-264: Dell OpenManage Server Administrator (OMSA) Security Update for Local Privilege Escalation via XSL Hijacking Vulnerability
Summary: Dell OpenManage Server Administrator (OMSA) remediation is available for Local Privilege Escalation via XSL Hijacking Vulnerability that could be exploited by malicious users to compromise the affected system. ...
This article applies to
This article does not apply to
This article is not tied to any specific product.
Not all product versions are identified in this article.
Impact
High
Details
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-37130 | Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability via XSL Hijacking. A local low-privileged malicious user could potentially exploit this vulnerability and escalate their privilege to the admin user and gain full control of the machine. Exploitation may lead to a complete system compromise. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-37130 | Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability via XSL Hijacking. A local low-privileged malicious user could potentially exploit this vulnerability and escalate their privilege to the admin user and gain full control of the machine. Exploitation may lead to a complete system compromise. | 7.3 | CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Affected Products & Remediation
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Dell OpenManage Server Administrator Managed Node for Windows | Versions prior to 11.0.1.1 | 11.0.1.1 | https://www.dell.com/support/home/en-us/drivers/driversdetails?driverid=NC2JJ |
| Dell OpenManage Server Administrator Managed Node for Windows | Versions prior to 11.0.0.2 | 11.0.0.2 | https://www.dell.com/support/home/en-us/drivers/driversdetails?driverid=KRRM7 |
| Dell OpenManage Server Administrator Managed Node for Windows | Versions prior to 10.3.0.1 | 10.3.0.1 | https://www.dell.com/support/home/en-us/drivers/driversdetails?driverid=GW01Y |
| Product | Affected Versions | Remediated Versions | Link |
|---|---|---|---|
| Dell OpenManage Server Administrator Managed Node for Windows | Versions prior to 11.0.1.1 | 11.0.1.1 | https://www.dell.com/support/home/en-us/drivers/driversdetails?driverid=NC2JJ |
| Dell OpenManage Server Administrator Managed Node for Windows | Versions prior to 11.0.0.2 | 11.0.0.2 | https://www.dell.com/support/home/en-us/drivers/driversdetails?driverid=KRRM7 |
| Dell OpenManage Server Administrator Managed Node for Windows | Versions prior to 10.3.0.1 | 10.3.0.1 | https://www.dell.com/support/home/en-us/drivers/driversdetails?driverid=GW01Y |
Revision History
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-06-10 | Initial release |
Related Information
Legal Disclaimer
Affected Products
OpenManage Server AdministratorArticle Properties
Article Number: 000225914
Article Type: Dell Security Advisory
Last Modified: 10 Jun 2024
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.