DSA-2022-217: Dell Command | Update and Dell Update/Alienware Update Security Update for a Local Privilege Escalation Vulnerability

概要: Dell Command | Update and Dell Update/Alienware Update remediation is available for a Local Privilege Escalation Vulnerability that may be exploited by malicious users to compromise the affected system. ...

この記事は次に適用されます: この記事は次には適用されません: この記事は、特定の製品に関連付けられていません。 すべての製品パージョンがこの記事に記載されているわけではありません。

影響

High

詳細

Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2022-34382 Dell Command | Update and Dell Update/Alienware Update versions before 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this vulnerability in order to elevate their privileges. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2022-34382 Dell Command | Update and Dell Update/Alienware Update versions before 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this vulnerability in order to elevate their privileges. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
デル・テクノロジーズでは、すべてのお客様に対して、CVSSベース スコアに加えて、特定のセキュリティの脆弱性に付随する潜在的な重要度に影響する可能性のある現状スコアや環境スコアも考慮することをお勧めしています。

影響を受ける製品と修復

Product Affected Versions Updated Versions Link to Update
Dell Command | Update Versions before 4.6.0 4.6.0 Universal Windows Platform version for Windows 10 32 and 64 bit
Dell Command | Update Application for Windows 10 | Driver Details | Dell US
Windows 32 and 64-bit version for Microsoft Windows 7, 8, 8.1, and 10
Dell Command | Update Application | Driver Details | Dell US
Dell Update/Alienware Update Versions before 4.6.0 4.6.0 Universal Windows Platform version for Windows 10 32 and 64 bit
Dell Update/Alienware Update Application for Windows 10 | Driver Details | Dell US
Windows 32 and 64-bit version for Microsoft Windows 7, 8, 8.1, and 10
Dell Update/Alienware Update Application | Driver Details | Dell US
Product Affected Versions Updated Versions Link to Update
Dell Command | Update Versions before 4.6.0 4.6.0 Universal Windows Platform version for Windows 10 32 and 64 bit
Dell Command | Update Application for Windows 10 | Driver Details | Dell US
Windows 32 and 64-bit version for Microsoft Windows 7, 8, 8.1, and 10
Dell Command | Update Application | Driver Details | Dell US
Dell Update/Alienware Update Versions before 4.6.0 4.6.0 Universal Windows Platform version for Windows 10 32 and 64 bit
Dell Update/Alienware Update Application for Windows 10 | Driver Details | Dell US
Windows 32 and 64-bit version for Microsoft Windows 7, 8, 8.1, and 10
Dell Update/Alienware Update Application | Driver Details | Dell US

変更履歴

RevisionDateDescription
1.02022-08-08Initial Release
1.12022-09-22Updated Link to Update

確認

Dell would like to thank Alexander Pudwill for reporting this issue.

関連情報

対象製品

Alienware Update, Dell Command | Update, Product Security Information
文書のプロパティ
文書番号: 000202198
文書の種類: Dell Security Advisory
最終更新: 08 6月 2023
質問に対する他のDellユーザーからの回答を見つける
サポート サービス
お使いのデバイスがサポート サービスの対象かどうかを確認してください。