Dell Update Package (DUP) Uncontrolled Search Path Vulnerability
CVE-2023-39254

7.3HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
1 March 2024

Summary

The vulnerability present in Dell Update Package (DUP) prior to version 4.9.10 stems from an Uncontrolled Search Path issue. This flaw could enable a malicious user, with local access to the affected system, to potentially exploit the vulnerability and execute arbitrary code with administrative privileges. This poses a significant security risk for users and organizations relying on affected versions of the software. Users are recommended to upgrade to the latest version to mitigate any risks associated with this vulnerability.

Affected Version(s)

DUP Framework < 4.9.10

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dohyun Lee
.