MEDIUM🇵🇱 Wersja polska

CVE-2019-3726

CVSS 6.7v3.1pub. 2019-09-24upd. 2024-11-21

An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versions prior to 19.1.0.413, and Framework file versions prior to 103.4.6.69 used in Dell EMC Servers. Dell Update Package (DUP) Framework file versions prior to 3.8.3.67 used in Dell Client Platforms. The vulnerability is limited to the DUP framework during the time window when a DUP is being executed by an administrator. During this time window, a locally authenticated low privilege malicious user potentially could exploit this vulnerability by tricking an administrator into running a trusted binary, causing it to load a malicious DLL and allowing the attacker to execute arbitrary code on the victim system. The vulnerability does not affect the actual binary payload that the DUP delivers.

CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
  • Dell Client Platforms

    HW
    Dell
    all versions
  • Dell Emc Servers

    HW
    Dell
    all versions
  • Dell Update Package Framework

    APP
    Dell
    < 3.8.3.67< 103.4.6.69< 19.1.0.413
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-23857HIGH8.2same product

Dell Update Package (DUP) Framework, versions 23.12.00 through 24.12.00, contains an Improper Handling of Insu...

CVE-2025-22395HIGH8.2same product

Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerabili...

CVE-2023-39254MEDIUM6.7same product

Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malic...

CVE-2023-32454MEDIUM6.3same product

DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerab...

CVE-2026-22769CRITICAL10.0⚠ KEVPL ✓same vendor

Dell RecoverPoint for VMs — zahardkodowane dane uwierzytelniające (RCE, root)