Dell Display Manager application, version 2.1.1.17, contains a vulnerability that low privilege user can execute malicious code during installation and uninstallation
The elevated privilege level required to perform operations such as chroot() should be dropped immediately after the operation is performed.
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://www.dell.com/support/kbdoc/en-us/000215216/dsa-2023-182-dell | patch vendor advisory |