Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-32479


Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in installed directory and taking reverse shell of the system leading to Privilege Escalation.


Published

2024-02-06T08:15:51.383

Last Modified

2024-11-21T08:03:26.443

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application dell encryption < 11.9.0 Yes
Application dell endpoint_security_suite_enterprise < 11.9.0 Yes
Application dell security_management_server < 11.9.0 Yes
Operating System microsoft windows - No

References