Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2024-7400

Disclosure Date: September 27, 2024 (last updated February 26, 2025)
The vulnerability potentially allowed an attacker to misuse ESET’s file operations during the removal of a detected file on the Windows operating system to delete files without having proper permissions to do so.
0
Attacker Value
Unknown

CVE-2023-32474

Disclosure Date: February 06, 2024 (last updated February 26, 2025)
Dell Display Manager application, version 2.1.1.17 and prior, contain an insecure operation on windows junction/mount point. A local malicious user could potentially exploit this vulnerability during installation leading to arbitrary folder or file deletion
Attacker Value
Unknown

CVE-2023-32454

Disclosure Date: February 06, 2024 (last updated February 26, 2025)
DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create arbitrary files, leading to denial of service
Attacker Value
Unknown

CVE-2023-5834

Disclosure Date: October 27, 2023 (last updated February 25, 2025)
HashiCorp Vagrant's Windows installer targeted a custom location with a non-protected path that could be junctioned, introducing potential for unauthorized file system writes. Fixed in Vagrant 2.4.0.
Attacker Value
Unknown

CVE-2023-40623

Disclosure Date: September 12, 2023 (last updated February 25, 2025)
SAP BusinessObjects Suite Installer - version 420, 430, allows an attacker within the network to create a directory under temporary directory and link it to a directory with operating system files. On successful exploitation the attacker can delete all the operating system files causing a limited impact on integrity and completely compromising the availability of the system.
Attacker Value
Unknown

CVE-2023-32470

Disclosure Date: September 08, 2023 (last updated February 25, 2025)
Dell Digital Delivery versions prior to 5.0.82.0 contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS).
Attacker Value
Unknown

CVE-2023-28065

Disclosure Date: June 23, 2023 (last updated February 25, 2025)
Dell Command | Update, Dell Update, and Alienware Update versions 4.8.0 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability leading to privilege escalation.
Attacker Value
Unknown

CVE-2023-28071

Disclosure Date: June 23, 2023 (last updated February 25, 2025)
Dell Command | Update, Dell Update, and Alienware Update versions 4.9.0, A01 and prior contain an Insecure Operation on Windows Junction / Mount Point vulnerability. A local malicious user could potentially exploit this vulnerability to create arbitrary folder leading to permanent Denial of Service (DOS).
Attacker Value
Unknown

CVE-2023-24572

Disclosure Date: February 13, 2023 (last updated February 24, 2025)
Dell Command | Integration Suite for System Center, versions before 6.4.0 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion.
Attacker Value
Unknown

CVE-2023-23697

Disclosure Date: February 13, 2023 (last updated February 24, 2025)
Dell Command | Intel vPro Out of Band, versions before 4.4.0, contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion.