CVE-2019-3749: Medium severity dell command | update vulnerability
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\ICProgress\DellInventoryCollectorProgress.xml" to any targeted file. This issue occurs because permissions on the Temp directory were set incorrectly.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3749?
CVE-2019-3749 is an Arbitrary File Deletion Vulnerability in Dell Command Update versions prior to 3.1.
How does CVE-2019-3749 affect Dell Command Update?
CVE-2019-3749 allows a local authenticated malicious user with low privileges to delete arbitrary files in Dell Command Update versions prior to 3.1.
What is the severity of CVE-2019-3749?
The severity of CVE-2019-3749 is medium, with a severity value of 5.5.
How can CVE-2019-3749 be exploited?
CVE-2019-3749 can be exploited by a local authenticated malicious user with low privileges who creates a symlink from the "Temp\ICProgress\Dell_InventoryCollector_Progress" directory.
Is there a fix available for CVE-2019-3749?
Yes, Dell Command Update version 3.1 or higher includes a fix for CVE-2019-3749.