DLL Injection Vulnerability in Dell OpenManage Server Administrator
CVE-2022-34396
7HIGH
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 1 February 2023
Summary
The vulnerability in Dell OpenManage Server Administrator versions up to 10.3.0.0 allows local low-privileged authenticated attackers to perform DLL injection. This may enable the execution of arbitrary code with elevated privileges, potentially compromising the entire system. Users are advised to apply the necessary security updates to mitigate risks associated with this vulnerability.
Affected Version(s)
OpenManage Server Administrator (OMSA) 0 <= 10.3.0.0
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved