Description
Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of an incomplete fix for CVE-2020-5358. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated privilege on the affected system with the help of a symbolic link.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-26567 | Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of an incomplete fix for CVE-2020-5358. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated privilege on the affected system with the help of a symbolic link. |
References
| Link | Providers |
|---|---|
| https://www.dell.com/support/article/SLN322456 |
|
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T02:01:32.478Z
Reserved: 2020-01-03T00:00:00.000Z
Link: CVE-2020-5385
No data.
Status : Modified
Published: 2020-08-18T21:15:12.363
Modified: 2024-11-21T05:34:02.353
Link: CVE-2020-5385
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD