Vulnerability Details CVE-2023-32479
Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in installed directory and taking reverse shell of the system leading to Privilege Escalation.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 12.4%
CVSS Severity
CVSS v3 Score 6.7
Products affected by CVE-2023-32479
-
cpe:2.3:a:dell:encryption:-
-
cpe:2.3:a:dell:encryption:10.0.0
-
cpe:2.3:a:dell:encryption:10.0.1
-
cpe:2.3:a:dell:encryption:10.4.0
-
cpe:2.3:a:dell:encryption:10.7.0
-
cpe:2.3:a:dell:encryption:10.8
-
cpe:2.3:a:dell:encryption:11.8.1
-
cpe:2.3:a:dell:encryption:8.0.0
-
cpe:2.3:a:dell:encryption:8.15.0
-
cpe:2.3:a:dell:encryption:8.16.0
-
cpe:2.3:a:dell:encryption:8.7.0
-
cpe:2.3:a:dell:endpoint_security_suite_enterprise:11.8.1
-
cpe:2.3:a:dell:endpoint_security_suite_enterprise:2.0.1
-
cpe:2.3:a:dell:endpoint_security_suite_enterprise:2.4.0
-
cpe:2.3:a:dell:endpoint_security_suite_enterprise:2.7
-
cpe:2.3:a:dell:endpoint_security_suite_enterprise:2.8
-
cpe:2.3:a:dell:security_management_server:10.2.0
-
cpe:2.3:a:dell:security_management_server:11.8.1
-
cpe:2.3:o:microsoft:windows:-