CVE-2023-39246: High severity dell endpoint security suite enterprise vulnerability
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server version prior to 11.8.1 contain an Insecure Operation on Windows Junction Vulnerability during installation. A local malicious user could potentially exploit this vulnerability to create an arbitrary folder inside a restricted directory, leading to Privilege Escalation
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Dell Encryption vulnerability?
The vulnerability ID is CVE-2023-39246.
What is the severity of CVE-2023-39246?
The severity of CVE-2023-39246 is high.
Which software versions are affected by CVE-2023-39246?
Dell Endpoint Security Suite Enterprise, Dell Encryption, and Dell Security Management Server versions prior to 11.8.1 are affected.
How can a local malicious user exploit CVE-2023-39246?
A local malicious user could potentially exploit CVE-2023-39246 to create an arbitrary folder during installation.
Where can I find more information about CVE-2023-39246?
You can find more information about CVE-2023-39246 on the Dell support website: https://www.dell.com/support/kbdoc/en-us/000217572/dsa-2023-271