CVE-2023-28071: High severity dell update vulnerability
Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this Dell Command | Update and Alienware Update vulnerability?
The vulnerability ID is CVE-2023-28071.
What is the severity of CVE-2023-28071?
The severity of CVE-2023-28071 is high with a score of 7.1.
What software versions are affected by CVE-2023-28071?
Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0 A01 and prior are affected by CVE-2023-28071.
How can a local malicious user exploit CVE-2023-28071?
A local malicious user can potentially exploit CVE-2023-28071 to create arbitrary folders leading to permanent Denial of Service.
Where can I find more information about CVE-2023-28071?
You can find more information about CVE-2023-28071 on the Dell support website: https://www.dell.com/support/kbdoc/en-us/000213546/dsa-2023-170-dell-command-update