DSA-2023-074: Dell Trusted Device Agent Security Update for an Improper Installation Permissions Vulnerability
Samenvatting: Dell Trusted Device Agent remediation is available for an improper installation permissions vulnerability that could be exploited by malicious users to compromise the affected system.
Dit artikel is van toepassing op
Dit artikel is niet van toepassing op
Dit artikel is niet gebonden aan een specifiek product.
Niet alle productversies worden in dit artikel vermeld.
Impact
High
Gegevens
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to escalated privileges. | 7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to escalated privileges. | 7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Getroffen producten en herstel
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
|---|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent | Versions prior to 5.3.0 |
5.3.0 | https://www.dell.com/support/home/product-support/product/trusted-device/drivers |
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
|---|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent | Versions prior to 5.3.0 |
5.3.0 | https://www.dell.com/support/home/product-support/product/trusted-device/drivers |
Tijdelijke oplossingen en risicobeperking
Uninstall and re-install Dell Trusted Device Agent with default settings.
Revisiegeschiedenis
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-04-04 | Initial Release |
Bevestigingen
CVE-2023-25542: Dell Technologies would like to thank Marius Gabriel Mihai for reporting this issue.
Verwante informatie
Juridische verklaring van afstand
Getroffen producten
Product Security Information, Dell Trusted DeviceArtikeleigenschappen
Artikelnummer: 000209461
Artikeltype: Dell Security Advisory
Laatst aangepast: 04 apr. 2023
Vind antwoorden op uw vragen via andere Dell gebruikers
Support Services
Controleer of uw apparaat wordt gedekt door Support Services.