Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-34384


Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may potentially exploit this vulnerability, leading to privilege escalation.


Published

2023-02-11T01:23:23.793

Last Modified

2024-11-21T07:09:24.463

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-250
  • Type: Primary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell alienware_update < 4.5.0 Yes
Application dell command_update < 4.5.0 Yes
Application dell supportassist_for_business_pcs ≤ 3.2.0 Yes
Application dell supportassist_for_home_pcs ≤ 3.11.2 Yes
Application dell update < 4.5.0 Yes

References