First published: Tue Aug 18 2020(Updated: )
Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of an incomplete fix for CVE-2020-5358. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated privilege on the affected system with the help of a symbolic link.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Data Protection | Encryption | <10.8 | |
Dell Endpoint Security Suite Enterprise | <2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Dell Encryption and Dell Endpoint Security Suite vulnerability is CVE-2020-5385.
The severity rating of CVE-2020-5385 is high with a score of 7.8.
The affected software for CVE-2020-5385 includes Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8.
The privilege escalation vulnerability in CVE-2020-5385 could allow a local malicious user with low privileges to gain elevated privileges.
To fix the privilege escalation vulnerability, it is recommended to update Dell Encryption to version 10.8 or later and Dell Endpoint Security Suite to version 2.8 or later.