ZeroHour

CVE-2024-52535

CVSS 3.1
8.8 high
EPSS
<1%p44
Published
()
Modified
Description

Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.

Vendors
dell
Products
supportassist for business pcs, supportassist for home pcs
Weakness
CWE-61, CWE-59
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.