DSA-2023-074: Dell Trusted Device Agent Security Update for an Improper Installation Permissions Vulnerability
Summary: Dell Trusted Device Agent remediation is available for an improper installation permissions vulnerability that could be exploited by malicious users to compromise the affected system.
Acest articol se aplică pentru
Acest articol nu se aplică pentru
Acest articol nu este legat de un produs specific.
Acest articol nu acoperă toate versiunile de produs existente.
Impact
High
Details
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to escalated privileges. | 7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| Proprietary Code CVE(s) | Description | CVSS Base Score | CVSS Vector String |
|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent, versions prior to 5.3.0, contain(s) an improper installation permissions vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to escalated privileges. | 7.0 | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Produse afectate și măsuri de remediere
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
|---|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent | Versions prior to 5.3.0 |
5.3.0 | https://www.dell.com/support/home/product-support/product/trusted-device/drivers |
| CVE(s) Addressed | Product | Affected Version(s) | Updated Version(s) | Link to Update |
|---|---|---|---|---|
| CVE-2023-25542 | Dell Trusted Device Agent | Versions prior to 5.3.0 |
5.3.0 | https://www.dell.com/support/home/product-support/product/trusted-device/drivers |
Soluții alternative și strategii de atenuare
Uninstall and re-install Dell Trusted Device Agent with default settings.
Revision History
| Revision | Date | Description |
|---|---|---|
| 1.0 | 2023-04-04 | Initial Release |
Acknowledgements
CVE-2023-25542: Dell Technologies would like to thank Marius Gabriel Mihai for reporting this issue.
Related Information
Exonerare de răspundere
Produse afectate
Product Security Information, Dell Trusted DeviceProprietăți articol
Article Number: 000209461
Article Type: Dell Security Advisory
Ultima modificare: 04 apr. 2023
Găsiți răspunsuri la întrebările dvs. de la alți utilizatori Dell
Servicii de asistență
Verificați dacă dispozitivul dvs. este acoperit de serviciile de asistență.