CVE-2024-52537

Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:dell:dock_hd22q_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

Configuration 2 (hide)

AND
cpe:2.3:a:dell:dock_hd22q_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

Configuration 3 (hide)

AND
cpe:2.3:a:dell:dock_wd19_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

Configuration 4 (hide)

AND
cpe:2.3:a:dell:dock_wd19_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

Configuration 5 (hide)

AND
cpe:2.3:a:dell:dock_wd22tb4_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

Configuration 6 (hide)

AND
cpe:2.3:a:dell:dock_wd22tb4_firmware_update_utility:*:*:*:*:*:*:*:*
OR cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*

History

04 Feb 2025, 16:13

Type Values Removed Values Added
CPE cpe:2.3:a:dell:dock_wd22tb4_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:x86:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:arm64:*
cpe:2.3:a:dell:dock_hd22q_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:a:dell:dock_wd19_firmware_update_utility:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Summary
  • (es) Dell Client Platform Firmware Update Utility contiene una vulnerabilidad de resolución de vínculo incorrecta. Un atacante con privilegios elevados y acceso local podría aprovechar esta vulnerabilidad, lo que provocaría una elevación de privilegios.
CWE CWE-59
References () https://www.dell.com/support/kbdoc/en-us/000227591/dsa-2024-351 - () https://www.dell.com/support/kbdoc/en-us/000227591/dsa-2024-351 - Vendor Advisory
First Time Dell dock Wd22tb4 Firmware Update Utility
Dell dock Wd19 Firmware Update Utility
Linux linux Kernel
Microsoft
Linux
Microsoft windows
Dell
Dell dock Hd22q Firmware Update Utility

11 Dec 2024, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-11 08:15

Updated : 2025-02-04 16:13


NVD link : CVE-2024-52537

Mitre link : CVE-2024-52537

CVE.ORG link : CVE-2024-52537


JSON object : View

Products Affected

dell

  • dock_hd22q_firmware_update_utility
  • dock_wd19_firmware_update_utility
  • dock_wd22tb4_firmware_update_utility

microsoft

  • windows

linux

  • linux_kernel
CWE
CWE-61

UNIX Symbolic Link (Symlink) Following

CWE-59

Improper Link Resolution Before File Access ('Link Following')