CVE-2023-32479

EUVD-2023-36723
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in installed directory and taking reverse shell of the system leading to Privilege Escalation.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.7 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
dellencryption
𝑥
< 11.9.0
dellendpoint_security_suite_enterprise
𝑥
< 11.9.0
dellsecurity_management_server
𝑥
< 11.9.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
dellsecurity_management_server
𝑥
< 11.9.0
ADP
dellendpoint_security_suite_enterprise
𝑥
< 11.9.0
ADP
dellencryption
𝑥
< 11.9.0
ADP