CVE-2023-32454

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
06/02/2024
Last modified:
13/02/2024

Description

<br /> DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create arbitrary files, leading to denial of service<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:update_package_framework:*:*:*:*:*:*:*:* 4.9.4.36 (including)


References to Advisories, Solutions, and Tools