DSA-2022-217: Dell Command | Update and Dell Update/Alienware Update Security Update for a Local Privilege Escalation Vulnerability

Resumo: Dell Command | Update and Dell Update/Alienware Update remediation is available for a Local Privilege Escalation Vulnerability that may be exploited by malicious users to compromise the affected system. ...

Este artigo aplica-se a Este artigo não se aplica a Este artigo não está vinculado a nenhum produto específico. Nem todas as versões do produto estão identificadas neste artigo.

Impacto

High

Dados

Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2022-34382 Dell Command | Update and Dell Update/Alienware Update versions before 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this vulnerability in order to elevate their privileges. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVE Description CVSS Base Score CVSS Vector String
CVE-2022-34382 Dell Command | Update and Dell Update/Alienware Update versions before 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this vulnerability in order to elevate their privileges. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
A Dell Technologies recomenda que todos os clientes levem em consideração a pontuação base CVSS e as pontuações temporais e ambientais pertinentes que possam afetar a gravidade potencial associada a uma vulnerabilidade de segurança específica.

Produtos afetados e soluções

Product Affected Versions Updated Versions Link to Update
Dell Command | Update Versions before 4.6.0 4.6.0 Universal Windows Platform version for Windows 10 32 and 64 bit
Dell Command | Update Application for Windows 10 | Driver Details | Dell US
Windows 32 and 64-bit version for Microsoft Windows 7, 8, 8.1, and 10
Dell Command | Update Application | Driver Details | Dell US
Dell Update/Alienware Update Versions before 4.6.0 4.6.0 Universal Windows Platform version for Windows 10 32 and 64 bit
Dell Update/Alienware Update Application for Windows 10 | Driver Details | Dell US
Windows 32 and 64-bit version for Microsoft Windows 7, 8, 8.1, and 10
Dell Update/Alienware Update Application | Driver Details | Dell US
Product Affected Versions Updated Versions Link to Update
Dell Command | Update Versions before 4.6.0 4.6.0 Universal Windows Platform version for Windows 10 32 and 64 bit
Dell Command | Update Application for Windows 10 | Driver Details | Dell US
Windows 32 and 64-bit version for Microsoft Windows 7, 8, 8.1, and 10
Dell Command | Update Application | Driver Details | Dell US
Dell Update/Alienware Update Versions before 4.6.0 4.6.0 Universal Windows Platform version for Windows 10 32 and 64 bit
Dell Update/Alienware Update Application for Windows 10 | Driver Details | Dell US
Windows 32 and 64-bit version for Microsoft Windows 7, 8, 8.1, and 10
Dell Update/Alienware Update Application | Driver Details | Dell US

Histórico de revisão

RevisionDateDescription
1.02022-08-08Initial Release
1.12022-09-22Updated Link to Update

Agradecimentos

Dell would like to thank Alexander Pudwill for reporting this issue.

Informações relacionadas

Produtos afetados

Alienware Update, Dell Command | Update, Product Security Information
Propriedades do artigo
Número do artigo: 000202198
Tipo de artigo: Dell Security Advisory
Último modificado: 08 jun. 2023
Encontre as respostas de outros usuários da Dell para suas perguntas.
Serviços de suporte
Verifique se o dispositivo está coberto pelos serviços de suporte.