Uncontrolled Search Path Element Vulnerability in Dell Peripheral Manager
CVE-2024-22447
6.7MEDIUM
What is CVE-2024-22447?
Dell Peripheral Manager versions before 1.7.3 are susceptible to an uncontrolled search path element vulnerability. This flaw enables an attacker to load malicious dynamic link libraries (DLLs) through preloading, which could lead to arbitrary code execution on the affected system. This vulnerability poses significant risks as it allows unauthorized access and execution of potentially harmful code, making it crucial for users to upgrade to the latest version to mitigate the threat.
Affected Version(s)
Peripheral Manager 0 < 1.7.3 or later
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dell Technologies would like to thank Yue Liu From TIANGONG Team of Legendsec at QI-ANXIN Group for reporting this issue.