DSA-2023-260: Security Update for a Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server Vulnerability

Riepilogo: Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server remediations are available for a privilege escalation vulnerability that could be exploited by malicious users to compromise the affected system. ...

Questo articolo si applica a Questo articolo non si applica a Questo articolo non è legato a un prodotto specifico. Non tutte le versioni del prodotto sono identificate in questo articolo.

Impatto

Medium

Dettagli

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-32479 Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in installed directory and taking reverse shell of the system leading to Privilege Escalation. 6.7
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2023-32479 Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in installed directory and taking reverse shell of the system leading to Privilege Escalation. 6.7
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies raccomanda a tutti i clienti di prendere in considerazione sia il punteggio base CVSS, sia ogni eventuale punteggio temporale o ambientale che possa avere effetti sul livello di gravità potenziale associato a una specifica vulnerabilità di sicurezza.

Prodotti interessati e correzione

Product
Software/Firmware
 
Affected Versions Remediated Versions Link
Dell Encryption
 
SW Versions prior to 11.9.0 Version 11.9.0 or later https://www.dell.com/support/home/product-support/product/dell-data-protection-encryption/drivers
 
Dell Endpoint Security Suite Enterprise SW Versions prior to 11.9.0 Version 11.9.0 or later https://www.dell.com/support/home/product-support/product/dell-dp-endpt-security-suite-enterprise/drivers
 
Dell Security Management Server (Windows) SW Versions prior to 11.9.0 Version 11.9.0 or later https://www.dell.com/support/home/product-support/product/dell-data-protection-encryption/drivers
 
Product
Software/Firmware
 
Affected Versions Remediated Versions Link
Dell Encryption
 
SW Versions prior to 11.9.0 Version 11.9.0 or later https://www.dell.com/support/home/product-support/product/dell-data-protection-encryption/drivers
 
Dell Endpoint Security Suite Enterprise SW Versions prior to 11.9.0 Version 11.9.0 or later https://www.dell.com/support/home/product-support/product/dell-dp-endpt-security-suite-enterprise/drivers
 
Dell Security Management Server (Windows) SW Versions prior to 11.9.0 Version 11.9.0 or later https://www.dell.com/support/home/product-support/product/dell-data-protection-encryption/drivers
 

Cronologia delle revisioni

RevisionDateDescription
1.02024-01-09Initial Release

Ringraziamenti

CVE-2023-32479: Dell would like to thank Pwni for reporting this issue. 

Informazioni correlate

Prodotti interessati

Dell Encryption, Dell Endpoint Security Suite Enterprise
Proprietà dell'articolo
Numero articolo: 000215881
Tipo di articolo: Dell Security Advisory
Ultima modifica: 09 gen 2024
Trova risposta alle tue domande dagli altri utenti Dell
Support Services
Verifica che il dispositivo sia coperto dai Servizi di supporto.