CVE-2023-32479

MEDIUM

Dell Encryption < 11.9.0 - Privilege Escalation via Improper ACL

Title source: llm
STIX 2.1

Description

Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in installed directory and taking reverse shell of the system leading to Privilege Escalation.

References (1)

Core 1
Core References

Scores

CVSS v3 6.7
EPSS 0.0004
EPSS Percentile 13.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (3)
dell/encryption < 11.9.0
dell/endpoint_security_suite_enterprise < 11.9.0
dell/security_management_server < 11.9.0
Published Feb 06, 2024
Tracked Since Feb 18, 2026