CVE-2023-23698: High severity dell update vulnerability
Dell Command | Update, Dell Update, and Alienware Update versions before 4.6.0 and 4.7.1 contain Insecure Operation on Windows Junction in the installer component. A local malicious user may potentially exploit this vulnerability leading to arbitrary file delete.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-23698?
CVE-2023-23698 is a vulnerability found in Dell Command | Update, Dell Update, and Alienware Update versions before 4.6.0 and 4.7.1 on Windows, which allows a local malicious user to potentially delete arbitrary files.
How severe is CVE-2023-23698?
CVE-2023-23698 has a severity rating of 7.1 (High).
Which software versions are affected by CVE-2023-23698?
Dell Command | Update versions before 4.6.0 and 4.7.1, Dell Update versions before 4.6.0 and 4.7.1, and Alienware Update versions before 4.6.0 and 4.7.1 are affected by CVE-2023-23698.
How can a local malicious user exploit CVE-2023-23698?
A local malicious user can exploit CVE-2023-23698 by taking advantage of an Insecure Operation on Windows Junction in the installer component, which may lead to arbitrary file deletion.
Where can I find more information about CVE-2023-23698?
More information about CVE-2023-23698 can be found at the following link: [Dell Support KB](https://www.dell.com/support/kbdoc/en-us/000208038/dsa-2023-031)