Description
Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46238 | Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system. |
References
History
Wed, 29 Jan 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dell
Dell supportassist For Business Pcs Dell supportassist For Home Pcs |
|
| Weaknesses | CWE-59 | |
| CPEs | cpe:2.3:a:dell:supportassist_for_business_pcs:*:*:*:*:*:*:*:* cpe:2.3:a:dell:supportassist_for_home_pcs:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Dell
Dell supportassist For Business Pcs Dell supportassist For Home Pcs |
Thu, 26 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 25 Dec 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system. | |
| Weaknesses | CWE-61 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-12-26T18:11:19.799Z
Reserved: 2024-11-12T06:04:07.775Z
Link: CVE-2024-52535
Updated: 2024-12-26T18:11:16.392Z
Status : Analyzed
Published: 2024-12-25T15:15:07.247
Modified: 2025-01-29T20:37:43.070
Link: CVE-2024-52535
No data.
OpenCVE Enrichment
No data.
EUVD