CVE-2020-5324
—CVSS 3.1
4.4 medium
EPSS
<1%p17
Published
()
Modified
Description
Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers.
- Vendors
- dell
- Products
- g3 3579 firmware, g3 3779 firmware, g3 15 3590 firmware, g5 15 5590 firmware, g5 5090 firmware, g5 5587 firmware, g7 15 7590 firmware, g7 17 7790 firmware, g7 7588 firmware, inspiron 14 5490 firmware, inspiron 3480 firmware, inspiron 3481 firmware
- Weakness
- CWE-427, CWE-59
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.