CVE-2023-23698
Published Feb 10, 2023
Last updated a year ago
Overview
- Description
- Dell Command | Update, Dell Update, and Alienware Update versions before 4.6.0 and 4.7.1 contain Insecure Operation on Windows Junction in the installer component. A local malicious user may potentially exploit this vulnerability leading to arbitrary file delete.
- Source
- security_alert@emc.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 3.1
- Type
- Primary
- Base score
- 7.1
- Impact score
- 5.2
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- Severity
- HIGH
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
- security_alert@emc.com
- CWE-1386
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:dell:alienware_update:4.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "10E69226-6D72-4E15-89C3-B95E00BF91A0" }, { "criteria": "cpe:2.3:a:dell:alienware_update:4.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4651608F-B893-4D9F-B3CB-AD3B9DC1EEE3" }, { "criteria": "cpe:2.3:a:dell:command_update:4.6.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9836FDEF-5971-45AE-AD0F-AEFB657F6AAB" }, { "criteria": "cpe:2.3:a:dell:command_update:4.7.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "350DEA8B-0DE7-4025-9124-ABA67D5CC8FC" } ], "operator": "OR" } ] } ]