Zip Bomb Vulnerability in Dell Hybrid Client Software
CVE-2022-34430

7.1HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
11 October 2022

Summary

Dell Hybrid Client versions prior to 1.8 are susceptible to a Zip Bomb vulnerability found in the user interface. This vulnerability allows an attacker with guest privileges to exploit the software, potentially leading to unauthorized modifications of system files. It's crucial for users to be aware of this security flaw to mitigate risks associated with such attacks.

Affected Version(s)

Dell Hybrid Client (DHC) < 1.8

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.