CVE-2024-52537

Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:dell:dock_hd22q_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

Configuration 2 (hide)

AND
cpe:2.3:a:dell:dock_hd22q_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

Configuration 3 (hide)

AND
cpe:2.3:a:dell:dock_wd19_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

Configuration 4 (hide)

AND
cpe:2.3:a:dell:dock_wd19_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

Configuration 5 (hide)

AND
cpe:2.3:a:dell:dock_wd22tb4_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

Configuration 6 (hide)

AND
cpe:2.3:a:dell:dock_wd22tb4_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

History

04 Feb 2025, 16:13

Type Values Removed Values Added
CWE CWE-59
References () https://www.dell.com/support/kbdoc/en-us/000227591/dsa-2024-351 - () https://www.dell.com/support/kbdoc/en-us/000227591/dsa-2024-351 - Vendor Advisory
Summary
  • (es) Dell Client Platform Firmware Update Utility contiene una vulnerabilidad de resolución de vínculo incorrecta. Un atacante con privilegios elevados y acceso local podría aprovechar esta vulnerabilidad, lo que provocaría una elevación de privilegios.
First Time Dell dock Hd22q Firmware Update Utility
Dell dock Wd19 Firmware Update Utility
Linux
Dell
Dell dock Wd22tb4 Firmware Update Utility
Microsoft windows
Linux linux Kernel
Microsoft
CPE cpe:2.3:a:dell:dock_hd22q_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*
cpe:2.3:a:dell:dock_wd19_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:dock_wd22tb4_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

11 Dec 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-11 08:15

Updated : 2025-02-04 16:13


NVD link : CVE-2024-52537

Mitre link : CVE-2024-52537

CVE.ORG link : CVE-2024-52537


JSON object : View

Products Affected

dell

  • dock_wd22tb4_firmware_update_utility
  • dock_wd19_firmware_update_utility
  • dock_hd22q_firmware_update_utility

linux

  • linux_kernel

microsoft

  • windows
CWE
CWE-61

UNIX Symbolic Link (Symlink) Following

CWE-59

Improper Link Resolution Before File Access ('Link Following')