Dell OpenManage Server Administrator Vulnerability: Local Privilege Escalation via XSL Hijacking
CVE-2024-37130
7.8HIGH
Key Information:
- Vendor
- Dell
- Vendor
- CVE Published:
- 11 June 2024
Summary
A vulnerability exists in Dell OpenManage Server Administrator that allows a low-privileged local user to exploit XSL Hijacking to escalate their privileges. Successful exploitation can grant the attacker administrative rights, enabling them to gain full control of the machine. This could lead to widespread system compromise, highlighting the importance of applying necessary security updates and mitigating risks associated with this vulnerability.
Affected Version(s)
Dell OpenManage Server Administrator < 11.0.1.1
Dell OpenManage Server Administrator < 11.0.0.2
Dell OpenManage Server Administrator < 10.3.0.1
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database