QID 378627
Date Published: 2023-07-18
QID 378627: Dell Command Update Windows Universal Application Vulnerability (DSA-2023-031)
Dell Command Update versions 4.6.0 and 4.7.1 contain Insecure Operation on Windows Junction in the installer component. A local malicious user may potentially exploit this vulnerability leading to arbitrary file delete.
Affected Versions:
Dell Command Update versions 4.6.0 and 4.7.1
QID Detection Logic:
This unauthenticated detection depends on the BlindElephant engine to detect the vulnerable version of the Ultimate Member WordPress plugin.
A local malicious user may potentially exploit Windows Universal Application Vulnerability leading to arbitrary file delete.
Solution
Customers are advised to upgrade to DSA-2023-031 or later version to remediate this vulnerability.
Vendor References
- DSA-2023-031 -
www.dell.com/support/kbdoc/en-in/000208038/dsa-2023-031
CVEs related to QID 378627
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| DSA-2023-031 |
|