Unknown
CVE-2020-5324
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2020-5324
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
Dell Client Consumer and Commercial Platforms contain an Arbitrary File Overwrite Vulnerability. The vulnerability is limited to the Dell Firmware Update Utility during the time window while being executed by an administrator. During this time window, a locally authenticated low-privileged malicious user could exploit this vulnerability by tricking an administrator into overwriting arbitrary files via a symlink attack. The vulnerability does not affect the actual binary payload that the update utility delivers.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- g3 15 3590 firmware,
- g3 3579 firmware,
- g3 3779 firmware,
- g5 15 5590 firmware,
- g5 5090 firmware,
- g5 5587 firmware,
- g7 15 7590 firmware,
- g7 17 7790 firmware,
- g7 7588 firmware,
- inspiron 14 5490 firmware,
- inspiron 3480 firmware,
- inspiron 3481 firmware,
- inspiron 3490 firmware,
- inspiron 3493 firmware,
- inspiron 3580 firmware,
- inspiron 3581 firmware,
- inspiron 3583 firmware,
- inspiron 3584 firmware,
- inspiron 3590 firmware,
- inspiron 3593 firmware,
- inspiron 3780 firmware,
- inspiron 3781 firmware,
- inspiron 3790 firmware,
- inspiron 3793 firmware,
- inspiron 5390 firmware,
- inspiron 5391 firmware,
- inspiron 5480 firmware,
- inspiron 5481 firmware,
- inspiron 5482 firmware,
- inspiron 5491 firmware,
- inspiron 5493 firmware,
- inspiron 5494 firmware,
- inspiron 5498 firmware,
- inspiron 5580 firmware,
- inspiron 5582 firmware,
- inspiron 5583 firmware,
- inspiron 5584 firmware,
- inspiron 5590 firmware,
- inspiron 5591 firmware,
- inspiron 5593 firmware,
- inspiron 5594 firmware,
- inspiron 5598 firmware,
- inspiron 7380 firmware,
- inspiron 7386 firmware,
- inspiron 7390 firmware,
- inspiron 7391 firmware,
- inspiron 7490 firmware,
- inspiron 7580 firmware,
- inspiron 7586 firmware,
- inspiron 7590 firmware,
- inspiron 7591 firmware,
- inspiron 7786 firmware,
- inspiron 7791 firmware,
- latitude 3300 firmware,
- latitude 3301 firmware,
- latitude 3311 firmware,
- latitude 3390 firmware,
- latitude 3400 firmware,
- latitude 3490 firmware,
- latitude 3500 firmware,
- latitude 3590 firmware,
- latitude 5290 firmware,
- latitude 5300 firmware,
- latitude 5400 firmware,
- latitude 5401 firmware,
- latitude 5420 rugged firmware,
- latitude 5424 rugged firmware,
- latitude 5490 firmware,
- latitude 5491 firmware,
- latitude 5500 firmware,
- latitude 5501 firmware,
- latitude 5590 firmware,
- latitude 5591 firmware,
- latitude 7200 firmware,
- latitude 7220 rugged extreme tablet firmware,
- latitude 7220ex rugged extreme tablet firmware,
- latitude 7290 firmware,
- latitude 7300 firmware,
- latitude 7390 firmware,
- latitude 7400 firmware,
- latitude 7424 rugged extreme firmware,
- latitude 7490 firmware,
- precision 3530 firmware,
- precision 3540 firmware,
- precision 3541 firmware,
- precision 5530 firmware,
- precision 5540 firmware,
- precision 7530 firmware,
- precision 7540 firmware,
- precision 7730 firmware,
- precision 7740 firmware,
- vostro 15 7580 firmware,
- vostro 3480 firmware,
- vostro 3481 firmware,
- vostro 3490 firmware,
- vostro 3580 firmware,
- vostro 3581 firmware,
- vostro 3583 firmware,
- vostro 3584 firmware,
- vostro 3590 firmware,
- vostro 5390 firmware,
- vostro 5391 firmware,
- vostro 5481 firmware,
- vostro 5490 firmware,
- vostro 5581 firmware,
- vostro 5590 firmware,
- vostro 7590 firmware,
- wyse 5070 thin client firmware,
- wyse 5470 firmware,
- xps 13 9380 firmware,
- xps 15 7590 firmware,
- xps 15 9570 firmware,
- xps 15 9575 firmware
References
Miscellaneous
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: