Privilege Escalation Vulnerability in Dell Encryption and Endpoint Security Suite
CVE-2020-5385

6.7MEDIUM

Key Information:

Vendor
Dell
Vendor
CVE Published:
18 August 2020

Summary

Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 are affected by a privilege escalation vulnerability due to an incomplete fix related to a previous issue. This allows local malicious users with limited privileges to exploit the vulnerability using symbolic links, potentially granting them elevated access on the affected systems. It's crucial for users to update their software to ensure protection against this vulnerability.

Affected Version(s)

Dell Encryption Enterprise < 10.8

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.