CVE-2024-52535
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/12/2024
Last modified:
29/01/2025
Description
Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.
Impact
Base Score 3.x
7.10
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:dell:supportassist_for_business_pcs:*:*:*:*:*:*:*:* | 4.5.1 (excluding) | |
cpe:2.3:a:dell:supportassist_for_home_pcs:*:*:*:*:*:*:*:* | 4.6.2 (excluding) |
To consult the complete list of CPE names with products and versions, see this page