CVE-2024-37142 HIGH

CVE-2024-37142

Vendor Dell
Product Dell Peripheral Manager
Weakness CWE-427
Published July 31, 2024
Last update July 31, 2024

CVSS base score

7.3/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and escalation of privilege

Key dates

02Disclosure timeline

July 31, 2024 CVE published
July 31, 2024 Record updated