CVE-2024-52537

Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:dell:dock_hd22q_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

Configuration 2 (hide)

AND
cpe:2.3:a:dell:dock_hd22q_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

Configuration 3 (hide)

AND
cpe:2.3:a:dell:dock_wd19_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

Configuration 4 (hide)

AND
cpe:2.3:a:dell:dock_wd19_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

Configuration 5 (hide)

AND
cpe:2.3:a:dell:dock_wd22tb4_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

Configuration 6 (hide)

AND
cpe:2.3:a:dell:dock_wd22tb4_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

History

04 Feb 2025, 16:13

Type Values Removed Values Added
CWE CWE-59
References () https://www.dell.com/support/kbdoc/en-us/000227591/dsa-2024-351 - () https://www.dell.com/support/kbdoc/en-us/000227591/dsa-2024-351 - Vendor Advisory
Summary
  • (es) Dell Client Platform Firmware Update Utility contiene una vulnerabilidad de resolución de vínculo incorrecta. Un atacante con privilegios elevados y acceso local podría aprovechar esta vulnerabilidad, lo que provocaría una elevación de privilegios.
First Time Dell dock Hd22q Firmware Update Utility
Dell dock Wd19 Firmware Update Utility
Linux
Dell
Dell dock Wd22tb4 Firmware Update Utility
Microsoft windows
Linux linux Kernel
Microsoft
CPE cpe:2.3:a:dell:dock_hd22q_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*
cpe:2.3:a:dell:dock_wd19_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:dock_wd22tb4_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

11 Dec 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-11 08:15

Updated : 2025-02-04 16:13


NVD link : CVE-2024-52537

Mitre link : CVE-2024-52537

CVE.ORG link : CVE-2024-52537


JSON object : View

Products Affected

dell

  • dock_hd22q_firmware_update_utility
  • dock_wd22tb4_firmware_update_utility
  • dock_wd19_firmware_update_utility

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-61

UNIX Symbolic Link (Symlink) Following

CWE-59

Improper Link Resolution Before File Access ('Link Following')