DLL Injection Vulnerability in Dell OpenManage Server Administrator
CVE-2022-34396

7HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
1 February 2023

Summary

The vulnerability in Dell OpenManage Server Administrator versions up to 10.3.0.0 allows local low-privileged authenticated attackers to perform DLL injection. This may enable the execution of arbitrary code with elevated privileges, potentially compromising the entire system. Users are advised to apply the necessary security updates to mitigate risks associated with this vulnerability.

Affected Version(s)

OpenManage Server Administrator (OMSA) 0 <= 10.3.0.0

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.