Arbitrary File Deletion Vulnerability in Dell Command Update by Dell
CVE-2019-3749
5.6MEDIUM
Summary
An Arbitrary File Deletion vulnerability exists in Dell Command Update versions prior to 3.1. This flaw allows a local authenticated user with limited privileges to potentially exploit the vulnerability by creating a symbolic link from the Temp directory to any targeted file, ultimately enabling the deletion of arbitrary files due to improper permission settings on the Temp directory.
Affected Version(s)
Dell Command Update (DCU) < 3.1
References
CVSS V3.1
Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved