VulnerabilityModified
CVE-2004-2359
Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray applet, which allows local users to gain privileges by accessing the Help functionality.
HIGH 10.0EPSS 5.74%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.74%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Dell TrueMobile 1300 WLAN Mini-PCI Card Util TrayApplet 3.10.39.0 does not properly drop SYSTEM privileges when started from the systray applet, which allows local users to gain privileges by accessing the Help functionality.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 5.74% probability · 93th percentile
- CISA KEV
- Not listed
- Affected
- dell/truemobile 1300 wlan mini-pci card util trayapplet
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0042.htmlVendor Advisory
- http://secunia.com/advisories/10949Vendor Advisory
- http://securitytracker.com/id?1009174Vendor Advisory
- http://www.securityfocus.com/bid/9714
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15285
- http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0042.htmlVendor Advisory
- http://secunia.com/advisories/10949Vendor Advisory
- http://securitytracker.com/id?1009174Vendor Advisory
- http://www.securityfocus.com/bid/9714
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15285
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.