Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-28071: DSA-2023-170: Dell Command | Update, Dell Update, and Alienware Update Security Update for an Insecure Operation on Windows Junction / Mount Point vulnerability

Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS).

CVE
#vulnerability#windows#microsoft#dos#dell

Vaikutus

Medium

Tiedot

Proprietary Code CVE(s)

Description

CVSS Base Score

CVSS Vector String

CVE-2023-28071

Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS).

6.3

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H

Proprietary Code CVE(s)

Description

CVSS Base Score

CVSS Vector String

CVE-2023-28071

Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS).

6.3

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H

Dell Technologies suosittelee, että kaikki asiakkaat ottavat huomioon sekä CVSS-peruspistemäärän että kaikki asiaankuuluvat väliaikaiset ja ympäristöön liittyvät pisteet, jotka voivat vaikuttaa tietyn tietoturvahaavoittuvuuden mahdolliseen vakavuuteen.

Tuotteet, joihin asia vaikuttaa ja tilanteen korjaaminen

Product

Software/Firmware

Affected Versions

Remediated Versions

Release Date (MM-DD-YYY) / Expected Release

Update link

Dell Command | Update

SW

4.9.0, A01 and Prior

4.9.0, A02

6/13/2023

Universal Windows Platform version for Windows 10 32-bit and 64-bit
https://www.dell.com/support/home/drivers/DriversDetails?driverId=J6PNP

Windows 32 and 64-bit version for Microsoft Windows 10
https://www.dell.com/support/home/drivers/DriversDetails?driverId=30F6M

Dell Update /
Alienware Update

SW

4.9.0, A01 and Prior

4.9.0, A02

6/13/2023

Universal Windows Platform version for Windows 10 32-bit and 64-bit
https://www.dell.com/support/home/en-us/drivers/DriversDetails?driverId=HF46K

Product

Software/Firmware

Affected Versions

Remediated Versions

Release Date (MM-DD-YYY) / Expected Release

Update link

Dell Command | Update

SW

4.9.0, A01 and Prior

4.9.0, A02

6/13/2023

Universal Windows Platform version for Windows 10 32-bit and 64-bit
https://www.dell.com/support/home/drivers/DriversDetails?driverId=J6PNP

Windows 32 and 64-bit version for Microsoft Windows 10
https://www.dell.com/support/home/drivers/DriversDetails?driverId=30F6M

Dell Update /
Alienware Update

SW

4.9.0, A01 and Prior

4.9.0, A02

6/13/2023

Universal Windows Platform version for Windows 10 32-bit and 64-bit
https://www.dell.com/support/home/en-us/drivers/DriversDetails?driverId=HF46K

Kiitokset

CVE-2023-28071: Dell Technologies would like to thank ycdxsb for reporting this issue.

Versiohistoria

Revision

Date

Description

1

2023-06-13

Initial Release

Asiaan liittyvät tiedot

Dell Security Advisories and Notices
Dell Vulnerability Response Policy
CVSS Scoring Guide

13 kesäk. 2023

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907