DSA-2023-074: Dell Trusted Device Agent Security Update for an Improper Installation Permissions Vulnerability
Resumen: Dell Trusted Device Agent remediation is available for an improper installation permissions vulnerability that could be exploited by malicious users to compromise the affected system.
Este artículo se aplica a:
Este artículo no se aplica a:
Este artículo no está vinculado a ningún producto específico.
En este artículo no se identifican todas las versiones de los productos.
Impacto
High
Detalles
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to escalated privileges. | 7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to escalated privileges. | 7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Productos afectados y corrección
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
|---|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent | Versions prior to 5.3.0 |
5.3.0 | https://www.dell.com/support/home/product-support/product/trusted-device/drivers |
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
|---|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent | Versions prior to 5.3.0 |
5.3.0 | https://www.dell.com/support/home/product-support/product/trusted-device/drivers |
Soluciones alternativas y mitigaciones
Uninstall and re-install Dell Trusted Device Agent with default settings.
Historial de revisiones
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-04-04 | Initial Release |
Agradecimientos
CVE-2023-25542: Dell Technologies would like to thank Marius Gabriel Mihai for reporting this issue.
Información relacionada
Aviso legal
Productos afectados
Product Security Information, Dell Trusted DevicePropiedades del artículo
Número de artículo: 000209461
Tipo de artículo: Dell Security Advisory
Última modificación: 04 abr 2023
Encuentra las respuestas que necesitas con la ayuda de otros usuarios de Dell
Servicios de asistencia
Comprueba si tu dispositivo está cubierto por los servicios de asistencia.