Dell OpenManage Server Administrator Vulnerability: Local Privilege Escalation via XSL Hijacking

CVE-2024-37130
7.3HIGH

Key Information

Vendor
Dell
Status
Dell Openmanage Server Administrator
Vendor
CVE Published:
11 June 2024

Summary

Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains a Local Privilege Escalation vulnerability via XSL Hijacking. A local low-privileged malicious user could potentially exploit this vulnerability and escalate their privilege to the admin user and gain full control of the machine. Exploitation may lead to a complete system compromise.

Affected Version(s)

Dell OpenManage Server Administrator < 11.0.1.1

Dell OpenManage Server Administrator < 11.0.0.2

Dell OpenManage Server Administrator < 10.3.0.1

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published.

  • Vulnerability Reserved.

Collectors

NVD DatabaseMitre Database
.