DSA-2023-182: Dell Display Manager Security Update for Multiple Vulnerabilities

Resumen: Dell Display Manager remediation is available for multiple vulnerabilities that may be exploited by malicious users to compromise the affected system.

Este artículo se aplica a Este artículo no se aplica a Este artículo no está vinculado a ningún producto específico. No se identifican todas las versiones del producto en este artículo.

Impacto

High

Detalles

Proprietary Code CVE(s) Description  CVSS Base Score CVSS Vector String
CVE-2023-32451 Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during installation and uninstallation. 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2023-32474 Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user could potentially exploit this vulnerability during installation leading to arbitrary folder or file deletion 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVE(s) Description  CVSS Base Score CVSS Vector String
CVE-2023-32451 Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during installation and uninstallation. 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
CVE-2023-32474 Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user could potentially exploit this vulnerability during installation leading to arbitrary folder or file deletion 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recomienda que todos los clientes tengan en cuenta tanto la puntuación base como cualquier otra puntuación ambiental y temporal relevante que pueda afectar la posible gravedad asociada con la vulnerabilidad de seguridad en particular.

Corrección y productos afectados

CVEs Addressed Product Software/Firmware Affected Versions  Remediated Versions Release Date (MM-DD-YYY) / Expected Release Link
CVE-2023-32451 Dell Display Manager SW Version 2.1.1.17 2.1.1.21 7/4/2023 Support for Dell Display Manager 2.x | Drivers & Downloads
CVE-2023-32474  Dell Display Manager SW Versions 2.1.1.17 and prior 2.1.1.21 7/4/2023 Support for Dell Display Manager 2.x | Drivers & Downloads
CVEs Addressed Product Software/Firmware Affected Versions  Remediated Versions Release Date (MM-DD-YYY) / Expected Release Link
CVE-2023-32451 Dell Display Manager SW Version 2.1.1.17 2.1.1.21 7/4/2023 Support for Dell Display Manager 2.x | Drivers & Downloads
CVE-2023-32474  Dell Display Manager SW Versions 2.1.1.17 and prior 2.1.1.21 7/4/2023 Support for Dell Display Manager 2.x | Drivers & Downloads
Dell recommends all customers update at the earliest opportunity.

Go to the Drivers & Downloads site for updates on the applicable products.

Customers may use one of the Dell notification solutions to be notified and download driver, BIOS, and firmware updates automatically once available.

Soluciones alternativas y mitigaciones

None.

Historial de revisiones

RevisionDateDescription
1.02023-07-07Initial Release

Reconocimientos

CVE-2023-32451, CVE-2023-32474: Dell Technologies would like to thank Marius Gabriel Mihai for reporting these issues.
 

Información relacionada

Propiedades del artículo
Número del artículo: 000215216
Tipo de artículo: Dell Security Advisory
Última modificación: 07 jul 2023
Encuentre respuestas a sus preguntas de otros usuarios de Dell
Servicios de soporte
Compruebe si el dispositivo está cubierto por los servicios de soporte.