CVE-2023-39254

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
01/03/2024
Last modified:
31/01/2025

Description

Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially exploit this vulnerability to run arbitrary code as admin.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:update_package_framework:*:*:*:*:*:*:*:* 4.9.10 (excluding)