First published: Tue Dec 03 2019(Updated: )
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to any targeted file. This issue occurs because of insecure handling of Temp directory permissions that were set incorrectly.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Command Update | <3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3750 is an Arbitrary File Deletion Vulnerability found in Dell Command Update versions prior to 3.1.
Anyone using Dell Command Update versions prior to 3.1 is affected by CVE-2019-3750.
CVE-2019-3750 has a severity rating of 5.5 (medium).
A local authenticated malicious user with low privileges can exploit CVE-2019-3750 by creating a symlink from the "Temp\IC\ICDebugLog.txt" to any targeted file, allowing them to delete arbitrary files.
To fix CVE-2019-3750, update Dell Command Update to version 3.1 or later.