PT-2024-1643 · Dell · Dell Display Manager
Marius Gabriel Mihai
·
Published
2024-02-06
·
Updated
2024-02-12
·
CVE-2023-32474
CVSS v3.1
6.6
Medium
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell Display Manager versions 2.1.1.17 and prior
Description
The issue is related to an insecure operation on Windows junction/mount points in the Dell Display Manager application. A local malicious user could potentially exploit this during installation, leading to arbitrary folder or file deletion. The vulnerability is associated with incorrect link resolution before accessing a file, which could allow an attacker to delete arbitrary files.
Recommendations
For versions 2.1.1.17 and prior, consider restricting access to the Dell Display Manager application during installation to minimize the risk of exploitation. As a temporary workaround, avoid using the application until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Insecure Operation on Windows Junction
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dell Display Manager