Dell Display Manager, versions 2.1.0 and prior, contains an arbitrary file or folder creation vulnerability during installation. A local low privilege attacker could potentially exploit this vulnerability, leading to the execution of arbitrary code on the operating system with high privileges.
The elevated privilege level required to perform operations such as chroot() should be dropped immediately after the operation is performed.
Link | Tags |
---|---|
https://www.dell.com/support/kbdoc/en-uk/000211727/dsa-2023 | patch vendor advisory |