Arbitrary File Overwrite Vulnerability in Dell Firmware Update Utility
CVE-2020-5324
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 21 February 2020
Summary
Dell Client Consumer and Commercial Platforms are impacted by an Arbitrary File Overwrite Vulnerability within the Dell Firmware Update Utility. This vulnerability allows a low-privileged attacker, with local access, to exploit the utility during its execution by an administrator. The attacker can achieve this by utilizing a symlink attack, potentially leading to the overwriting of arbitrary files. Importantly, the integrity of the binary payload delivered by the update utility remains unaffected. Effective security practices and immediate remediation are recommended to mitigate the risks associated with this vulnerability.
Affected Version(s)
Dell Client Consumer and Commercial Platforms https://www.dell.com/support/article/SLN320348
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved