Dell SupportAssist for Home PCs version 3.14.1 and prior versions contain a privilege escalation vulnerability in the installer. A local low privileged authenticated attacker may potentially exploit this vulnerability, leading to the execution of arbitrary executable on the operating system with elevated privileges.
References
Configurations
History
02 Jan 2024, 20:02
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.dell.com/support/kbdoc/en-us/000220677/dsa-2023-468-security-update-for-dell-supportassist-for-home-pcs-installer-file-local-privilege-escalation-vulnerability - Vendor Advisory | |
CPE | cpe:2.3:a:dell:supportassist_for_home_pcs:3.14.2.45116:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.8 |
CWE | CWE-426 |
22 Dec 2023, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-12-22 16:15
Updated : 2024-02-05 00:22
NVD link : CVE-2023-48670
Mitre link : CVE-2023-48670
CVE.ORG link : CVE-2023-48670
JSON object : View
Products Affected
dell
- supportassist_for_home_pcs
CWE
CWE-426
Untrusted Search Path