DSA-2023-146: Dell Command | Update, Dell Update, and Alienware Update Security Update for a Privilege Escalation Vulnerability
Resumen: Dell Command | Update, Dell Update, and Alienware Update remediation is available for a Privilege Escalation Vulnerability that could be exploited by malicious users to compromise the affected system. ...
Este artículo se aplica a:
Este artículo no se aplica a:
Este artículo no está vinculado a ningún producto específico.
En este artículo no se identifican todas las versiones de los productos.
Impacto
Medium
Detalles
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
| CVE-2023-28065 | Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalation. | 6.7 | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
| CVE-2023-28065 | Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalation. | 6.7 | CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H |
Productos afectados y corrección
| Product | Affected Version(s) | Updated Version(s) | Link to Update |
| Dell Command | Update |
4.8.0 and prior |
4.9.0 |
Universal Windows Platform version for Windows 10 32-bit and 64-bit Dell Command | Update Application for Windows 10 | Driver Details | Dell US Windows 32 and 64-bit versions for Microsoft Windows 10 Dell Command | Update Application | Driver Details | Dell US |
| Dell Update / Alienware Update |
4.8.0 and prior |
4.9.0 |
Universal Windows Platform version for Windows 10 32-bit and 64-bit Dell Update/Alienware Update Application for Windows 10 | Driver Details | Dell US |
| Product | Affected Version(s) | Updated Version(s) | Link to Update |
| Dell Command | Update |
4.8.0 and prior |
4.9.0 |
Universal Windows Platform version for Windows 10 32-bit and 64-bit Dell Command | Update Application for Windows 10 | Driver Details | Dell US Windows 32 and 64-bit versions for Microsoft Windows 10 Dell Command | Update Application | Driver Details | Dell US |
| Dell Update / Alienware Update |
4.8.0 and prior |
4.9.0 |
Universal Windows Platform version for Windows 10 32-bit and 64-bit Dell Update/Alienware Update Application for Windows 10 | Driver Details | Dell US |
Soluciones alternativas y mitigaciones
None.
Historial de revisiones
| Revision | Date | Description |
| 1.0 | 2023-05-09 | Initial Release |
Agradecimientos
CVE-2023-28065: Dell Technologies would like to thank Marius Gabriel Mihai for reporting this issue.
Información relacionada
Aviso legal
Productos afectados
Alienware Update, Dell Command | Update, Dell Update, Product Security InformationPropiedades del artículo
Número de artículo: 000212574
Tipo de artículo: Dell Security Advisory
Última modificación: 09 may 2023
Encuentra las respuestas que necesitas con la ayuda de otros usuarios de Dell
Servicios de asistencia
Comprueba si tu dispositivo está cubierto por los servicios de asistencia.