Description
Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the Dell Dock Firmware Update Utilities during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-26539 | Dell Dock Firmware Update Utilities for Dell Client Consumer and Commercial docking stations contain an Arbitrary File Overwrite vulnerability. The vulnerability is limited to the Dell Dock Firmware Update Utilities during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers. |
References
| Link | Providers |
|---|---|
| https://www.dell.com/support/article/SLN321564 |
|
History
No history.
Subscriptions
Dell
Subscribe
Dock Wd15
Subscribe
Dock Wd15 Firmware
Subscribe
Dock Wd19
Subscribe
Dock Wd19 Firmware
Subscribe
Precision Dual Usb-c Thunderbolt Dock - Tb18dc
Subscribe
Precision Dual Usb-c Thunderbolt Dock - Tb18dc Firmware
Subscribe
Thunderbolt Dock Tb16
Subscribe
Thunderbolt Dock Tb16 Firmware
Subscribe
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-16T22:09:55.405Z
Reserved: 2020-01-03T00:00:00.000Z
Link: CVE-2020-5357
No data.
Status : Modified
Published: 2020-05-28T20:15:12.037
Modified: 2024-11-21T05:33:58.487
Link: CVE-2020-5357
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD