PT-2024-2775 · Dell · Dell Alienware Command Center

Published

2024-04-10

·

Updated

2025-01-31

·

CVE-2024-22450

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Dell Alienware Command Center versions prior to 6.2.7.0
Description The issue is related to an uncontrolled search path element, which could allow a local malicious user to inject malicious files into the file search path. This could lead to system compromise. Exploitation of the vulnerability may enable an attacker to execute arbitrary code by injecting specially crafted files into the search path.
Recommendations For versions prior to 6.2.7.0, update to version 6.2.7.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the file search path to minimize the risk of exploitation. Avoid using the vulnerable search path functionality until the issue is resolved.

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2024-02913
CVE-2024-22450

Affected Products

Dell Alienware Command Center