CVE-2019-3749

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
03/12/2019
Last modified:
10/12/2019

Description

Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\ICProgress\Dell_InventoryCollector_Progress.xml" to any targeted file. This issue occurs because permissions on the Temp directory were set incorrectly.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:command_update:*:*:*:*:*:*:*:* 3.1 (excluding)


References to Advisories, Solutions, and Tools