CVE-2023-23698

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/02/2023
Last modified:
07/11/2023

Description

<br /> Dell Command | Update, Dell Update, and Alienware Update versions before 4.6.0 and 4.7.1 contain Insecure Operation on Windows Junction in the installer component. A local malicious user may potentially exploit this vulnerability leading to arbitrary file delete.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:alienware_update:4.6.0:*:*:*:*:*:*:*
cpe:2.3:a:dell:alienware_update:4.7.1:*:*:*:*:*:*:*
cpe:2.3:a:dell:command_update:4.6.0:*:*:*:*:*:*:*
cpe:2.3:a:dell:command_update:4.7.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools