Zip Bomb Vulnerability in Dell Hybrid Client Software
CVE-2022-34430
7.1HIGH
Summary
Dell Hybrid Client versions prior to 1.8 are susceptible to a Zip Bomb vulnerability found in the user interface. This vulnerability allows an attacker with guest privileges to exploit the software, potentially leading to unauthorized modifications of system files. It's crucial for users to be aware of this security flaw to mitigate risks associated with such attacks.
Affected Version(s)
Dell Hybrid Client (DHC) < 1.8
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved