Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers.

Project Subscriptions

Vendors Products
G3 15 3590 Subscribe
G3 15 3590 Firmware Subscribe
G3 3579 Subscribe
G3 3579 Firmware Subscribe
G3 3779 Subscribe
G3 3779 Firmware Subscribe
G5 15 5590 Subscribe
G5 15 5590 Firmware Subscribe
G5 5090 Subscribe
G5 5090 Firmware Subscribe
G5 5587 Subscribe
G5 5587 Firmware Subscribe
G7 15 7590 Subscribe
G7 15 7590 Firmware Subscribe
G7 17 7790 Subscribe
G7 17 7790 Firmware Subscribe
G7 7588 Subscribe
G7 7588 Firmware Subscribe
Inspiron 14 5490 Subscribe
Inspiron 14 5490 Firmware Subscribe
Inspiron 3480 Subscribe
Inspiron 3480 Firmware Subscribe
Inspiron 3481 Subscribe
Inspiron 3481 Firmware Subscribe
Inspiron 3490 Subscribe
Inspiron 3490 Firmware Subscribe
Inspiron 3493 Subscribe
Inspiron 3493 Firmware Subscribe
Inspiron 3580 Subscribe
Inspiron 3580 Firmware Subscribe
Inspiron 3581 Subscribe
Inspiron 3581 Firmware Subscribe
Inspiron 3583 Subscribe
Inspiron 3583 Firmware Subscribe
Inspiron 3584 Subscribe
Inspiron 3584 Firmware Subscribe
Inspiron 3590 Subscribe
Inspiron 3590 Firmware Subscribe
Inspiron 3593 Subscribe
Inspiron 3593 Firmware Subscribe
Inspiron 3780 Subscribe
Inspiron 3780 Firmware Subscribe
Inspiron 3781 Subscribe
Inspiron 3781 Firmware Subscribe
Inspiron 3790 Subscribe
Inspiron 3790 Firmware Subscribe
Inspiron 3793 Subscribe
Inspiron 3793 Firmware Subscribe
Inspiron 5390 Subscribe
Inspiron 5390 Firmware Subscribe
Inspiron 5391 Subscribe
Inspiron 5391 Firmware Subscribe
Inspiron 5480 Subscribe
Inspiron 5480 Firmware Subscribe
Inspiron 5481 Subscribe
Inspiron 5481 Firmware Subscribe
Inspiron 5482 Subscribe
Inspiron 5482 Firmware Subscribe
Inspiron 5491 Subscribe
Inspiron 5491 Firmware Subscribe
Inspiron 5493 Subscribe
Inspiron 5493 Firmware Subscribe
Inspiron 5494 Subscribe
Inspiron 5494 Firmware Subscribe
Inspiron 5498 Subscribe
Inspiron 5498 Firmware Subscribe
Inspiron 5580 Subscribe
Inspiron 5580 Firmware Subscribe
Inspiron 5582 Subscribe
Inspiron 5582 Firmware Subscribe
Inspiron 5583 Subscribe
Inspiron 5583 Firmware Subscribe
Inspiron 5584 Subscribe
Inspiron 5584 Firmware Subscribe
Inspiron 5590 Subscribe
Inspiron 5590 Firmware Subscribe
Inspiron 5591 Subscribe
Inspiron 5591 Firmware Subscribe
Inspiron 5593 Subscribe
Inspiron 5593 Firmware Subscribe
Inspiron 5594 Subscribe
Inspiron 5594 Firmware Subscribe
Inspiron 5598 Subscribe
Inspiron 5598 Firmware Subscribe
Inspiron 7380 Subscribe
Inspiron 7380 Firmware Subscribe
Inspiron 7386 Subscribe
Inspiron 7386 Firmware Subscribe
Inspiron 7390 Subscribe
Inspiron 7390 Firmware Subscribe
Inspiron 7391 Subscribe
Inspiron 7391 Firmware Subscribe
Inspiron 7490 Subscribe
Inspiron 7490 Firmware Subscribe
Inspiron 7580 Subscribe
Inspiron 7580 Firmware Subscribe
Inspiron 7586 Subscribe
Inspiron 7586 Firmware Subscribe
Inspiron 7590 Subscribe
Inspiron 7590 Firmware Subscribe
Inspiron 7591 Subscribe
Inspiron 7591 Firmware Subscribe
Inspiron 7786 Subscribe
Inspiron 7786 Firmware Subscribe
Inspiron 7791 Subscribe
Inspiron 7791 Firmware Subscribe
Latitude 3300 Subscribe
Latitude 3300 Firmware Subscribe
Latitude 3301 Subscribe
Latitude 3301 Firmware Subscribe
Latitude 3311 Subscribe
Latitude 3311 Firmware Subscribe
Latitude 3390 Subscribe
Latitude 3390 Firmware Subscribe
Latitude 3400 Subscribe
Latitude 3400 Firmware Subscribe
Latitude 3490 Subscribe
Latitude 3490 Firmware Subscribe
Latitude 3500 Subscribe
Latitude 3500 Firmware Subscribe
Latitude 3590 Subscribe
Latitude 3590 Firmware Subscribe
Latitude 5290 Subscribe
Latitude 5290 Firmware Subscribe
Latitude 5300 Subscribe
Latitude 5300 Firmware Subscribe
Latitude 5400 Subscribe
Latitude 5400 Firmware Subscribe
Latitude 5401 Subscribe
Latitude 5401 Firmware Subscribe
Latitude 5420 Rugged Subscribe
Latitude 5420 Rugged Firmware Subscribe
Latitude 5424 Rugged Subscribe
Latitude 5424 Rugged Firmware Subscribe
Latitude 5490 Subscribe
Latitude 5490 Firmware Subscribe
Latitude 5491 Subscribe
Latitude 5491 Firmware Subscribe
Latitude 5500 Subscribe
Latitude 5500 Firmware Subscribe
Latitude 5501 Subscribe
Latitude 5501 Firmware Subscribe
Latitude 5590 Subscribe
Latitude 5590 Firmware Subscribe
Latitude 5591 Subscribe
Latitude 5591 Firmware Subscribe
Latitude 7200 Subscribe
Latitude 7200 Firmware Subscribe
Latitude 7220 Rugged Extreme Tablet Subscribe
Latitude 7220 Rugged Extreme Tablet Firmware Subscribe
Latitude 7220ex Rugged Extreme Tablet Subscribe
Latitude 7220ex Rugged Extreme Tablet Firmware Subscribe
Latitude 7290 Subscribe
Latitude 7290 Firmware Subscribe
Latitude 7300 Subscribe
Latitude 7300 Firmware Subscribe
Latitude 7390 Subscribe
Latitude 7390 Firmware Subscribe
Latitude 7400 Subscribe
Latitude 7400 Firmware Subscribe
Latitude 7424 Rugged Extreme Subscribe
Latitude 7424 Rugged Extreme Firmware Subscribe
Latitude 7490 Subscribe
Latitude 7490 Firmware Subscribe
Precision 3530 Subscribe
Precision 3530 Firmware Subscribe
Precision 3540 Subscribe
Precision 3540 Firmware Subscribe
Precision 3541 Subscribe
Precision 3541 Firmware Subscribe
Precision 5530 Subscribe
Precision 5530 Firmware Subscribe
Precision 5540 Subscribe
Precision 5540 Firmware Subscribe
Precision 7530 Subscribe
Precision 7530 Firmware Subscribe
Precision 7540 Subscribe
Precision 7540 Firmware Subscribe
Precision 7730 Subscribe
Precision 7730 Firmware Subscribe
Precision 7740 Subscribe
Precision 7740 Firmware Subscribe
Vostro 15 7580 Subscribe
Vostro 15 7580 Firmware Subscribe
Vostro 3480 Subscribe
Vostro 3480 Firmware Subscribe
Vostro 3481 Subscribe
Vostro 3481 Firmware Subscribe
Vostro 3490 Subscribe
Vostro 3490 Firmware Subscribe
Vostro 3580 Subscribe
Vostro 3580 Firmware Subscribe
Vostro 3581 Subscribe
Vostro 3581 Firmware Subscribe
Vostro 3583 Subscribe
Vostro 3583 Firmware Subscribe
Vostro 3584 Subscribe
Vostro 3584 Firmware Subscribe
Vostro 3590 Subscribe
Vostro 3590 Firmware Subscribe
Vostro 5390 Subscribe
Vostro 5390 Firmware Subscribe
Vostro 5391 Subscribe
Vostro 5391 Firmware Subscribe
Vostro 5481 Subscribe
Vostro 5481 Firmware Subscribe
Vostro 5490 Subscribe
Vostro 5490 Firmware Subscribe
Vostro 5581 Subscribe
Vostro 5581 Firmware Subscribe
Vostro 5590 Subscribe
Vostro 5590 Firmware Subscribe
Vostro 7590 Subscribe
Vostro 7590 Firmware Subscribe
Wyse 5070 Thin Client Subscribe
Wyse 5070 Thin Client Firmware Subscribe
Wyse 5470 Subscribe
Wyse 5470 Firmware Subscribe
Xps 13 9380 Subscribe
Xps 13 9380 Firmware Subscribe
Xps 15 7590 Subscribe
Xps 15 7590 Firmware Subscribe
Xps 15 9570 Subscribe
Xps 15 9570 Firmware Subscribe
Xps 15 9575 Subscribe
Xps 15 9575 Firmware Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2020-26506 Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-17T02:16:34.647Z

Reserved: 2020-01-03T00:00:00

Link: CVE-2020-5324

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-02-21T15:15:12.047

Modified: 2024-11-21T05:33:54.747

Link: CVE-2020-5324

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses