VulnerabilityAnalyzed
CVE-2023-43078
Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.
HIGH 7.3EPSS 0.17%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.17%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.
- CVSS 3.1
- 7.3 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.17% probability · 7th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- dell/intel thunderbolt controller firmware update utility · dell/tpm 2.0 firmware update utility · dell/alienware m15 r6 firmware · dell/alienware m15 r7 firmware · dell/alienware m16 r1 firmware · dell/alienware m18 r1 firmware · dell/alienware x14 r2 firmware · dell/alienware x16 r1 firmware · dell/chengming 3900 firmware · dell/chengming 3910 firmware · dell/chengming 3911 firmware · dell/chengming 3988 firmware · dell/chengming 3990 firmware · dell/chengming 3991 firmware · dell/g15 5510 firmware · dell/g15 5511 firmware · dell/g15 5520 firmware · dell/g15 5530 firmware · dell/g16 7620 firmware · dell/g16 7630 firmware · +40 more
- Source
- security_alert@emc.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.