DSA-2024-033: Security Update for a Dell Digital Delivery Vulnerability
Résumé: Dell Digital Delivery remediation is available for a Use After Free vulnerability that could be exploited by malicious users to compromise the affected system.
Cet article concerne
Cet article ne concerne pas
Cet article n’est associé à aucun produit spécifique.
Toutes les versions du produit ne sont pas identifiées dans cet article.
Impact
High
Détails
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-0155 | Dell Digital Delivery, versions prior to 5.2.0.0, contain a Use After Free Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to application crash or execution of arbitrary code. | 7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Proprietary Code CVEs | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2024-0155 | Dell Digital Delivery, versions prior to 5.2.0.0, contain a Use After Free Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to application crash or execution of arbitrary code. | 7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Produits concernés et mesure corrective
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Release Date(MM/DD/YYYY) | Link |
|---|---|---|---|---|---|
| CVE-2024-0155 | Dell Digital Delivery | Versions prior to 5.2.0.0 | Version 5.2.0.0 | 08/01/2024 | https://www.dell.com/support/kbdoc/en-us/000192053/how-to-download-and-install-dell-digital-delivery |
| CVEs Addressed | Product | Affected Versions | Remediated Versions | Release Date(MM/DD/YYYY) | Link |
|---|---|---|---|---|---|
| CVE-2024-0155 | Dell Digital Delivery | Versions prior to 5.2.0.0 | Version 5.2.0.0 | 08/01/2024 | https://www.dell.com/support/kbdoc/en-us/000192053/how-to-download-and-install-dell-digital-delivery |
Solutions de contournement et mesures d’atténuation
None
Historique des révisions
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2024-03-01 | Initial Release |
| 2.0 | 2024-08-20 | Updated Affected Products and Remediation section Updated CVE description to update version |
Remerciements
Dell Technologies would like to thank Yue Liu From TIANGONG Team of Legendsec at QI-ANXIN Group for reporting this issue.
Informations connexes
Mention légale
Produits concernés
UtilitiesPropriétés de l’article
Numéro d’article: 000222292
Type d’article: Dell Security Advisory
Dernière modification: 20 août 2024
Trouvez des réponses à vos questions auprès d’autres utilisateurs Dell
Services de support
Vérifiez si votre appareil est couvert par les services de support.