CVE-2018-11063

Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software installs multiple services incorrectly by specifying the paths to the service executables without quotes. This could potentially allow a low-privileged local user to execute arbitrary executables with elevated privileges.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:wyse_management_suite:*:*:*:*:pro:*:*:*
cpe:2.3:a:dell:wyse_management_suite:*:*:*:*:standard:*:*:*

History

21 Nov 2024, 03:42

Type Values Removed Values Added
References () https://www.dell.com/support/article/us/en/19/sln313398/dell-wyse-management-suite-multiple-unquoted-service-path-vulnerabilities?lang=en - Vendor Advisory () https://www.dell.com/support/article/us/en/19/sln313398/dell-wyse-management-suite-multiple-unquoted-service-path-vulnerabilities?lang=en - Vendor Advisory

Information

Published : 2018-08-10 20:29

Updated : 2024-11-21 03:42


NVD link : CVE-2018-11063

Mitre link : CVE-2018-11063

CVE.ORG link : CVE-2018-11063


JSON object : View

Products Affected

dell

  • wyse_management_suite
CWE
CWE-428

Unquoted Search Path or Element