CVE-2022-34387

Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:dell:supportassist_for_business_pcs:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:supportassist_for_home_pcs:*:*:*:*:*:*:*:*

History

21 Nov 2024, 07:09

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 7.8
v2 : unknown
v3 : 6.4
References () https://www.dell.com/support/kbdoc/000204114 - Vendor Advisory () https://www.dell.com/support/kbdoc/000204114 - Vendor Advisory

07 Nov 2023, 03:48

Type Values Removed Values Added
Summary Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system. Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system.

Information

Published : 2023-02-11 01:23

Updated : 2024-11-21 07:09


NVD link : CVE-2022-34387

Mitre link : CVE-2022-34387

CVE.ORG link : CVE-2022-34387


JSON object : View

Products Affected

dell

  • supportassist_for_business_pcs
  • supportassist_for_home_pcs
CWE
CWE-377

Insecure Temporary File

CWE-668

Exposure of Resource to Wrong Sphere