Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2025-2773 | Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary remote scripts on the server. Exploitation may lead to a denial of service by an attacker. |
Solution
No solution given by the vendor.
Workaround
Recommend users not to use Extract option in Microsoft Windows OS if the File Version of update package is less than 22.01.02. If it is less than 22.01.02 we suggest using extract option via command prompt.
Tue, 04 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Dell
Dell update Package Framework |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:dell:update_package_framework:*:*:*:*:*:*:*:* | |
Vendors & Products |
Dell
Dell update Package Framework |
Tue, 07 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 07 Jan 2025 03:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary remote scripts on the server. Exploitation may lead to a denial of service by an attacker. | |
Weaknesses | CWE-280 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: dell
Published:
Updated: 2025-01-07T15:42:03.579Z
Reserved: 2025-01-06T13:40:01.387Z
Link: CVE-2025-22395

Updated: 2025-01-07T15:41:49.702Z

Status : Analyzed
Published: 2025-01-07T03:15:06.047
Modified: 2025-02-04T15:49:52.617
Link: CVE-2025-22395

No data.

No data.