PT-2024-21240 · Dell · Dell Grab For Windows

CVE-2024-25956

·

Published

2024-03-26

·

Updated

2024-03-26

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Dell Grab for Windows versions 5.0.4 and below
Description The issue is related to improper file permissions, which could be exploited by a locally authenticated attacker to disclose certain system information. A locally authenticated attacker could potentially exploit this vulnerability, leading to information disclosure.
Recommendations For versions 5.0.4 and below, update to a version above 5.0.4 to resolve the issue. As a temporary workaround, consider restricting access to sensitive system information to minimize the risk of exploitation.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-25956

Affected Products

Dell Grab For Windows