CVE-2024-38305

Dell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the installer. A local low-privileged authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary executables on the operating system with elevated privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:dell:supportassist_for_home_pcs:4.0.3:*:*:*:*:*:*:*

History

25 Nov 2024, 18:16

Type Values Removed Values Added
CPE cpe:2.3:a:dell:supportassist_for_home_pcs:4.0.3:*:*:*:*:*:*:*
Summary
  • (es) Dell SupportAssist for Home PCs Installer exe versión 4.0.3 contiene una vulnerabilidad de escalada de privilegios en el instalador. Un atacante local autenticado con pocos privilegios podría explotar esta vulnerabilidad, lo que llevaría a la ejecución de ejecutables arbitrarios en el sistema operativo con privilegios elevados.
First Time Dell supportassist For Home Pcs
Dell
References () https://www.dell.com/support/kbdoc/en-us/000227899/dsa-2024-312-security-update-for-dell-supportassist-for-home-pcs-installer-file-local-privilege-escalation-vulnerability - () https://www.dell.com/support/kbdoc/en-us/000227899/dsa-2024-312-security-update-for-dell-supportassist-for-home-pcs-installer-file-local-privilege-escalation-vulnerability - Vendor Advisory

21 Aug 2024, 03:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-21 03:15

Updated : 2024-11-25 18:16


NVD link : CVE-2024-38305

Mitre link : CVE-2024-38305

CVE.ORG link : CVE-2024-38305


JSON object : View

Products Affected

dell

  • supportassist_for_home_pcs
CWE
CWE-426

Untrusted Search Path