Dell Digital Delivery versions prior to 3.5.2015 contain an incorrect default permissions vulnerability. A locally authenticated low-privileged malicious user could exploit this vulnerability to run an arbitrary executable with administrative privileges on the affected system.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://www.dell.com/support/article/SLN320561 | patch vendor advisory |