PT-2024-21242 · Dell · Dell Grab For Windows

Published

2024-03-26

·

Updated

2024-03-27

·

CVE-2024-25958

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Grab for Windows versions up to and including 5.0.4
Description The issue allows a local authenticated attacker to potentially exploit Weak Application Folder Permissions, leading to privilege escalation, unauthorized access to application data, unauthorized modification of application data, and service disruption.
Recommendations For versions up to and including 5.0.4, update to a version later than 5.0.4 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2024-25958

Affected Products

Dell Grab For Windows