PT-2024-28536 · Dell · Dell Power Manager
Lefteris Panos
·
Published
2024-08-21
·
Updated
2024-11-26
·
CVE-2024-39576
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dell Power Manager versions 3.15.0 and prior
Description
The issue is related to an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to code execution and elevation of privileges. The vulnerability involves an insecure DCOM deserialization, allowing elevation to SYSTEM.
Recommendations
For versions 3.15.0 and prior, update to a version later than 3.15.0 to resolve the issue. As a temporary workaround, consider restricting local access to minimize the risk of exploitation.
Fix
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dell Power Manager