PT-2024-1643 · Dell · Dell Display Manager

Marius Gabriel Mihai

·

Published

2024-02-06

·

Updated

2024-02-12

·

CVE-2023-32474

CVSS v3.1

6.6

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Display Manager versions 2.1.1.17 and prior
Description The issue is related to an insecure operation on Windows junction/mount points in the Dell Display Manager application. A local malicious user could potentially exploit this during installation, leading to arbitrary folder or file deletion. The vulnerability is associated with incorrect link resolution before accessing a file, which could allow an attacker to delete arbitrary files.
Recommendations For versions 2.1.1.17 and prior, consider restricting access to the Dell Display Manager application during installation to minimize the risk of exploitation. As a temporary workaround, avoid using the application until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insecure Operation on Windows Junction

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01317
CVE-2023-32474

Affected Products

Dell Display Manager