CVE-2018-11063
Summary
| CVE | CVE-2018-11063 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-10 20:29:00 UTC |
| Updated | 2018-10-16 17:09:00 UTC |
| Description | Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software installs multiple services incorrectly by specifying the paths to the service executables without quotes. This could potentially allow a low-privileged local user to execute arbitrary executables with elevated privileges. |
Risk And Classification
Problem Types: CWE-428
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dell | Wyse Management Suite | All | All | All | All |
| Application | Dell | Wyse Management Suite | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Dell Wyse Management Suite Multiple Unquoted Service Path Vulnerabilities | Dell US | MISC | www.dell.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.