First published: Fri Mar 01 2024(Updated: )
Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially exploit this vulnerability to run arbitrary code as admin.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell Update Package Framework | <4.9.10 | |
Dell Update | <4.9.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39254 has a severity rating that indicates it allows local users to potentially execute arbitrary code with administrative privileges.
To fix CVE-2023-39254, upgrade to Dell Update Package version 4.9.10 or later.
CVE-2023-39254 affects users of Dell Update Package versions prior to 4.9.10.
CVE-2023-39254 is classified as an Uncontrolled Search Path vulnerability.
CVE-2023-39254 requires local access for exploitation, so it cannot be exploited remotely.