2024-07-14 02:06:08 +00:00

60 lines
2.2 KiB
JSON

{
"id": "CVE-2024-25958",
"sourceIdentifier": "security_alert@emc.com",
"published": "2024-03-26T16:15:11.917",
"lastModified": "2024-03-26T17:09:53.043",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to privilege escalation, unauthorized access to application data, unauthorized modification of application data and service disruption."
},
{
"lang": "es",
"value": "Dell Grab para Windows, versiones hasta la 5.0.4 incluida, contiene una vulnerabilidad de permisos de carpeta de aplicaciones d\u00e9biles. Un atacante autenticado local podr\u00eda explotar esta vulnerabilidad, lo que provocar\u00eda una escalada de privilegios, acceso no autorizado a los datos de la aplicaci\u00f3n, modificaci\u00f3n no autorizada de los datos de la aplicaci\u00f3n e interrupci\u00f3n del servicio."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "security_alert@emc.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "HIGH",
"privilegesRequired": "LOW",
"userInteraction": "REQUIRED",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 6.7,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 0.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "security_alert@emc.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-276"
}
]
}
],
"references": [
{
"url": "https://www.dell.com/support/kbdoc/en-us/000223508/dsa-2024-121-security-update-for-grab-for-windows-vulnerabilities",
"source": "security_alert@emc.com"
}
]
}