Lucene search

K
cveDellCVE-2022-34387
HistoryFeb 11, 2023 - 1:23 a.m.

CVE-2022-34387

2023-02-1101:23:24
CWE-377
CWE-668
dell
web.nvd.nist.gov
24
cve-2022-34387
dell
supportassist
home pcs
business pcs
privilege escalation
vulnerability

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0

Percentile

5.1%

Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system.

Affected configurations

Nvd
Vulners
Node
dellsupportassist_for_business_pcsRange3.2.0
OR
dellsupportassist_for_home_pcsRange3.11.4
VendorProductVersionCPE
dellsupportassist_for_business_pcs*cpe:2.3:a:dell:supportassist_for_business_pcs:*:*:*:*:*:*:*:*
dellsupportassist_for_home_pcs*cpe:2.3:a:dell:supportassist_for_home_pcs:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SupportAssist",
    "vendor": "Dell",
    "versions": [
      {
        "lessThanOrEqual": "3.11.4, 3.2.0",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.8

Confidence

High

EPSS

0

Percentile

5.1%

Related for CVE-2022-34387