PT-2023-26846 · Dell+1 · Dell Encryption+3

CVE-2023-39246

·

Publicado

2023-11-16

·

Atualizado

2023-11-29

CVSS v3.1

7.3

Alta

VetorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Encryption versions prior to 11.8.1 Dell Endpoint Security Suite Enterprise versions prior to 11.8.1 Dell Security Management Server versions prior to 11.8.1
Description The issue is related to an Insecure Operation on Windows Junction Vulnerability that occurs during installation. A local malicious user could potentially exploit this to create an arbitrary folder inside a restricted directory, leading to Privilege Escalation.
Recommendations For Dell Encryption versions prior to 11.8.1, update to version 11.8.1 or later. For Dell Endpoint Security Suite Enterprise versions prior to 11.8.1, update to version 11.8.1 or later. For Dell Security Management Server versions prior to 11.8.1, update to version 11.8.1 or later.

Correção

Link Following

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-39246

Produtos afetados

Dell Encryption
Dell Endpoint Security Suite Enterprise
Dell Security Management Server
Windows