First published: Tue Dec 03 2019(Updated: )
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\ICProgress\Dell_InventoryCollector_Progress.xml" to any targeted file. This issue occurs because permissions on the Temp directory were set incorrectly.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Command Update | <3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3749 is an Arbitrary File Deletion Vulnerability in Dell Command Update versions prior to 3.1.
CVE-2019-3749 allows a local authenticated malicious user with low privileges to delete arbitrary files in Dell Command Update versions prior to 3.1.
The severity of CVE-2019-3749 is medium, with a severity value of 5.5.
CVE-2019-3749 can be exploited by a local authenticated malicious user with low privileges who creates a symlink from the "Temp\ICProgress\Dell_InventoryCollector_Progress" directory.
Yes, Dell Command Update version 3.1 or higher includes a fix for CVE-2019-3749.