CVE-2019-3744
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Dell/Alienware Digital Delivery versions prior to 4.0.41 contain a privilege escalation vulnerability. A local non-privileged malicious user could exploit a Universal Windows Platform application by manipulating the install software package feature with a race condition and a path traversal exploit in order to run a malicious executable with elevated privileges.
Dell/Alienware Digital Delivery en versiones anteriores a 4.0.41, contiene una vulnerabilidad de escalamiento de privilegios. Un usuario malicioso local no privilegiado podría explotar una aplicación de la Plataforma de Windows Universal mediante la manipulación de la funcionalidad de instalación de paquete de software con una condición de carrera y una explotación de salto de ruta (path) para correr un ejecutable malicioso con privilegios elevados.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-03 CVE Reserved
- 2019-08-09 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.dell.com/support/article/SLN318085 | 2023-03-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Dell Search vendor "Dell" | Digital Delivery Search vendor "Dell" for product "Digital Delivery" | < 3.5.2013 Search vendor "Dell" for product "Digital Delivery" and version " < 3.5.2013" | - |
Affected
| ||||||
Dell Search vendor "Dell" | Digital Delivery Search vendor "Dell" for product "Digital Delivery" | >= 4.0.15.0 < 4.0.41 Search vendor "Dell" for product "Digital Delivery" and version " >= 4.0.15.0 < 4.0.41" | - |
Affected
|