CVE-2024-25958

MEDIUM

Dell Grab <= 5.0.4 - Authenticated Privilege Escalation via Weak Application Folder Permissions

Title source: llm
STIX 2.1

Description

Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to privilege escalation, unauthorized access to application data, unauthorized modification of application data and service disruption.

Scores

CVSS v3 6.7
EPSS 0.0003
EPSS Percentile 10.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-276
Status published
Products (1)
dell/grab < 5.0.5
Published Mar 26, 2024
Tracked Since Feb 18, 2026