Overview
- Description
- Dell Command Update, Dell Update and Alienware Update versions prior to 4.6.0 contains a Local Privilege Escalation Vulnerability in the custom catalog configuration. A local malicious user may potentially exploit this vulnerability in order to elevate their privileges.
- Source
- security_alert@emc.com
- NVD status
- Analyzed
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
Weaknesses
- nvd@nist.gov
- NVD-CWE-noinfo
Social media
- Hype score
- Not currently trending
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:dell:alienware_update:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "92EC7ABF-252B-4679-B923-B3C2F396FE03", "versionEndExcluding": "4.6.0" }, { "criteria": "cpe:2.3:a:dell:command_update:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "2456776C-8FB3-41AA-9124-0F1B377457E9", "versionEndExcluding": "4.6.0" }, { "criteria": "cpe:2.3:a:dell:update:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "05188818-03F7-4238-92E4-EA4E6D84D9CD", "versionEndExcluding": "4.6.0" } ], "operator": "OR" } ] } ]