CVE-2023-32479: High severity dell data protection | encryption vulnerability
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in installed directory and taking reverse shell of the system leading to Privilege Escalation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-32479?
CVE-2023-32479 is classified as a privilege escalation vulnerability.
How do I fix CVE-2023-32479?
To mitigate CVE-2023-32479, update to Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server version 11.9.0 or later.
Who is affected by CVE-2023-32479?
CVE-2023-32479 affects users of Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0.
What causes CVE-2023-32479?
CVE-2023-32479 is caused by improper access control lists (ACLs) of the non-default installation directories in affected Dell products.
Can a remote attacker exploit CVE-2023-32479?
No, CVE-2023-32479 can only be exploited by a local malicious user.