CVE-2024-52535

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/12/2024
Last modified:
29/01/2025

Description

Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:dell:supportassist_for_business_pcs:*:*:*:*:*:*:*:* 4.5.1 (excluding)
cpe:2.3:a:dell:supportassist_for_home_pcs:*:*:*:*:*:*:*:* 4.6.2 (excluding)