DSA-2023-170: Dell Command | Update, Dell Update, and Alienware Update Security Update for an Insecure Operation on Windows Junction / Mount Point vulnerability

Résumé: Dell Command | Update, Dell Update, and Alienware Update remediation is available for an Insecure Operation on Windows Junction / Mount Point vulnerability that could be exploited by malicious users to compromise the affected system. ...

Cet article concerne Cet article ne concerne pas Cet article n’est associé à aucun produit spécifique. Toutes les versions du produit ne sont pas identifiées dans cet article.

Impact

Medium

Détails

Proprietary Code CVE(s) Description  CVSS Base Score CVSS Vector String
CVE-2023-28071
Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS).
6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Proprietary Code CVE(s) Description  CVSS Base Score CVSS Vector String
CVE-2023-28071
Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS).
6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H
Dell Technologies recommande à tous les clients de prendre en compte à la fois le score de base CVSS et les scores temporels et environnementaux pertinents qui peuvent avoir un impact sur la gravité potentielle associée à une faille de sécurité donnée.

Produits concernés et mesure corrective

Product Software/Firmware Affected Versions  Remediated Versions Release Date (MM-DD-YYY) / Expected Release Update link
Dell Command | Update SW 4.9.0, A01 and Prior 4.9.0, A02 6/13/2023 Universal Windows Platform version for Windows 10 32-bit and 64-bit
https://www.dell.com/support/home/drivers/DriversDetails?driverId=J6PNP
Windows 32 and 64-bit version for Microsoft Windows 10
https://www.dell.com/support/home/drivers/DriversDetails?driverId=30F6M
Dell Update /
Alienware Update
SW 4.9.0, A01 and Prior 4.9.0, A02 6/13/2023 Universal Windows Platform version for Windows 10 32-bit and 64-bit
https://www.dell.com/support/home/en-us/drivers/DriversDetails?driverId=HF46K
Product Software/Firmware Affected Versions  Remediated Versions Release Date (MM-DD-YYY) / Expected Release Update link
Dell Command | Update SW 4.9.0, A01 and Prior 4.9.0, A02 6/13/2023 Universal Windows Platform version for Windows 10 32-bit and 64-bit
https://www.dell.com/support/home/drivers/DriversDetails?driverId=J6PNP
Windows 32 and 64-bit version for Microsoft Windows 10
https://www.dell.com/support/home/drivers/DriversDetails?driverId=30F6M
Dell Update /
Alienware Update
SW 4.9.0, A01 and Prior 4.9.0, A02 6/13/2023 Universal Windows Platform version for Windows 10 32-bit and 64-bit
https://www.dell.com/support/home/en-us/drivers/DriversDetails?driverId=HF46K

Historique des révisions

RevisionDateDescription
12023-06-13Initial Release

Remerciements

CVE-2023-28071: Dell Technologies would like to thank ycdxsb for reporting this issue.

Informations connexes

Produits concernés

Alienware Update, Dell Command | Update, Dell Update
Propriétés de l’article
Numéro d’article: 000213546
Type d’article: Dell Security Advisory
Dernière modification: 13 juin 2023
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.