CVE-2023-39254: High severity dell update package framework vulnerability
Published Mar 1, 2024
·Updated
Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially exploit this vulnerability to run arbitrary code as admin.
Affected Software
2 affected components
Dell Update Package Framework<4.9.10
Dell Update Package<4.9.10
Event History
Mar 1, 2024
CVE Published
via MITRE·12:43 PM
Data Sourced
via MITRE·12:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-39254?
CVE-2023-39254 has a severity rating that indicates it allows local users to potentially execute arbitrary code with administrative privileges.
2
How do I fix CVE-2023-39254?
To fix CVE-2023-39254, upgrade to Dell Update Package version 4.9.10 or later.
3
Who is affected by CVE-2023-39254?
CVE-2023-39254 affects users of Dell Update Package versions prior to 4.9.10.
4
What type of vulnerability is CVE-2023-39254?
CVE-2023-39254 is classified as an Uncontrolled Search Path vulnerability.
5
Can CVE-2023-39254 be exploited remotely?
CVE-2023-39254 requires local access for exploitation, so it cannot be exploited remotely.