CVE-2019-3750

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
03/12/2019
Last modified:
10/12/2019

Description

Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to any targeted file. This issue occurs because of insecure handling of Temp directory permissions that were set incorrectly.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:command_update:*:*:*:*:*:*:*:* 3.1 (excluding)


References to Advisories, Solutions, and Tools