CVE-2019-3750

MEDIUM

Dell Command Update < 3.1 - Symlink Following

Title source: rule

Description

Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to any targeted file. This issue occurs because of insecure handling of Temp directory permissions that were set incorrectly.

Scores

CVSS v3 5.5
EPSS 0.0005
EPSS Percentile 14.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-427 CWE-59
Status published

Affected Products (1)

dell/command_update < 3.1

Timeline

Published Dec 03, 2019
Tracked Since Feb 18, 2026