Arbitrary File Overwrite Vulnerability in Dell Firmware Update Utility
CVE-2020-5324

7.1HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
21 February 2020

Summary

Dell Client Consumer and Commercial Platforms are impacted by an Arbitrary File Overwrite Vulnerability within the Dell Firmware Update Utility. This vulnerability allows a low-privileged attacker, with local access, to exploit the utility during its execution by an administrator. The attacker can achieve this by utilizing a symlink attack, potentially leading to the overwriting of arbitrary files. Importantly, the integrity of the binary payload delivered by the update utility remains unaffected. Effective security practices and immediate remediation are recommended to mitigate the risks associated with this vulnerability.

Affected Version(s)

Dell Client Consumer and Commercial Platforms https://www.dell.com/support/article/SLN320348

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.