Arbitrary File Deletion Vulnerability in Dell Command Update
CVE-2019-3750
5.6MEDIUM
Summary
An arbitrary file deletion vulnerability exists in Dell Command Update prior to version 3.1 due to improper permissions on the Temp directory. A local authenticated user with minimal privileges can exploit this flaw by creating a symbolic link from the Temp directory's 'ICDebugLog.txt' to any targeted file, potentially leading to unauthorized deletion of important system files. Organizations are urged to update to the latest version to mitigate this security risk.
Affected Version(s)
Dell Command Update (DCU) < 3.1
References
CVSS V3.1
Score:
5.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved