CVE-2019-3750
MEDIUMDell Command Update < 3.1 - Symlink Following
Title source: ruleDescription
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to any targeted file. This issue occurs because of insecure handling of Temp directory permissions that were set incorrectly.
Scores
CVSS v3
5.5
EPSS
0.0005
EPSS Percentile
14.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-427
CWE-59
Status
published
Affected Products (1)
dell/command_update
< 3.1
Timeline
Published
Dec 03, 2019
Tracked Since
Feb 18, 2026