Home
MEDIUM: 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HDefault status
unaffected
Any version before 1.7.3 or later
affected
Description
Dell Peripheral Manager, versions prior to 1.7.3, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious dll., leading to arbitrary code execution.
Problem types
CWE-427: Uncontrolled Search Path Element
Product status
Any version before 1.7.3 or later
Credits
Dell Technologies would like to thank Yue Liu From TIANGONG Team of Legendsec at QI-ANXIN Group for reporting this issue.
References
www.dell.com/...-search-path-element-vulnerabilities?lang=en