Lucene search

K
cveDellCVE-2019-3744
HistoryAug 09, 2019 - 7:15 p.m.

CVE-2019-3744

2019-08-0919:15:11
CWE-362
CWE-22
dell
web.nvd.nist.gov
98
dell
alienware
digital delivery
cve-2019-3744
privilege escalation
vulnerability
nvd
security
race condition
path traversal
exploit
uwp

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

9.9%

Dell/Alienware Digital Delivery versions prior to 4.0.41 contain a privilege escalation vulnerability. A local non-privileged malicious user could exploit a Universal Windows Platform application by manipulating the install software package feature with a race condition and a path traversal exploit in order to run a malicious executable with elevated privileges.

Affected configurations

Nvd
Node
delldigital_deliveryRange<3.5.2013
OR
delldigital_deliveryRange4.0.15.04.0.41
VendorProductVersionCPE
delldigital_delivery*cpe:2.3:a:dell:digital_delivery:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Dell Digital Delivery",
    "vendor": "Dell",
    "versions": [
      {
        "status": "affected",
        "version": "prior to 4.0.41"
      }
    ]
  },
  {
    "product": "Alienware Digital Delivery",
    "vendor": "Dell",
    "versions": [
      {
        "status": "affected",
        "version": "prior to 4.0.41"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.6

Confidence

High

EPSS

0

Percentile

9.9%

Related for CVE-2019-3744