QID 378534

Date Published: 2023-06-07

QID 378534: Dell Client Security Update for Intel Driver Vulnerabilities (DSA-2021-237)

Dell has released an advisory to address CVE-2020-8741 and CVE-2021-0110 CVE-2020-8741: Improper permissions in the installer for the Intel(R) Thunderbolt(TM) non-DCH driver, all versions, for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2021-0110: Improper access control in some Intel(R) Thunderbolt(TM) Windows DCH Drivers may allow unauthenticated user to potentially enable denial of service via local access.

Affected Products:
Dell Latitude 5420 Prior to Driver Version 1.41.1193.0

Note: This QID only covers Dell Latitude 5420 Model

QID Detection Logic
: This QID checks if Vulnerable version of driver installed on windows system.

Successful exploitation may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Customers are recommended to update bios firmware. Refer to dsa-2021-237 for driver updates.

    CVEs related to QID 378534

    Software Advisories
    Advisory ID Software Component Link
    dsa-2021-237 URL Logo www.dell.com/support/kbdoc/en-in/000193312/dsa-2021-237