PT-2024-1644 · Dell · Dell Security Management Server+2
Pwni
·
Published
2024-02-06
·
Updated
2024-04-01
·
CVE-2023-32479
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell Encryption versions prior to 11.9.0
Dell Endpoint Security Suite Enterprise versions prior to 11.9.0
Dell Security Management Server versions prior to 11.9.0
Description
The issue is related to a privilege escalation vulnerability due to improper Access Control List (ACL) settings in the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in the installed directory, leading to privilege escalation. This could allow an attacker to gain elevated privileges on the system.
Recommendations
For Dell Encryption versions prior to 11.9.0, update to version 11.9.0 or later to resolve the issue.
For Dell Endpoint Security Suite Enterprise versions prior to 11.9.0, update to version 11.9.0 or later to resolve the issue.
For Dell Security Management Server versions prior to 11.9.0, update to version 11.9.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the non-default installation directory to minimize the risk of exploitation.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Encryption
Dell Endpoint Security Suite Enterprise
Dell Security Management Server