// For flags

CVE-2019-3745

 

Severity Score

7.3
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite Enterprise versions prior to 2.4.0. This issue is exploitable only during the installation of the product by an administrator. A local authenticated low privileged user potentially could exploit this vulnerability by staging a malicious DLL in the search path of the installer prior to its execution by a local administrator. This would cause loading of the malicious DLL, which would allow the attacker to execute arbitrary code in the context of an administrator.

La vulnerabilidad esta limitada para los instaladores de Dell Encryption Enterprise versiones anteriores a 10.4.0 y Dell Endpoint Security Suite Enterprise versiones anteriores a 2.4.0. Este problema es explotable solo durante la instalación del producto por parte de un administrador. Un usuario poco privilegiado local y autenticado podría explotar esta vulnerabilidad diseñando una DLL maliciosa en la ruta de búsqueda del instalador antes de que un administrador local la ejecute. Esto causaría la carga de la DLL maliciosa, lo que permitiría al atacante ejecutar código arbitrario en el contexto de un administrador.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
High
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Local
Attack Complexity
Medium
Authentication
None
Confidentiality
Complete
Integrity
Complete
Availability
Complete
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2019-01-03 CVE Reserved
  • 2019-10-07 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-09-17 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-426: Untrusted Search Path
  • CWE-427: Uncontrolled Search Path Element
CAPEC
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Dell
Search vendor "Dell"
Encryption
Search vendor "Dell" for product "Encryption"
< 10.4.0
Search vendor "Dell" for product "Encryption" and version " < 10.4.0"
enterprise
Affected
Dell
Search vendor "Dell"
Endpoint Security Suite Enterprise
Search vendor "Dell" for product "Endpoint Security Suite Enterprise"
< 2.4.0
Search vendor "Dell" for product "Endpoint Security Suite Enterprise" and version " < 2.4.0"
-
Affected