20040222 Dell TrueMobile Wireless Help Privilege Escalation Vulnerabilitymailing list
http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0042.html CVE-2004-2359
Dell TrueMobile 1300 WLAN System 3.10.39.0 Tray Applet - Local Privilege Escalation
Record summary
CVE-2004-2359 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit.
Description
Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray applet, which allows local users to gain privileges by accessing the Help functionality.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBDell TrueMobile 1300 WLAN System 3.10.39.0 Tray Applet - Local Privilege EscalationExploitDB exploitby Ian VitekNot analyzed1 file
References
610949Third-party advisory
http://secunia.com/advisories/10949 1009174vdb entry
http://securitytracker.com/id?1009174 9714vdb entry
http://www.securityfocus.com/bid/9714 dell-truemobile-gain-privileges(15285)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15285 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-2359