CVE-2024-28964
CVSS V2 None
CVSS V3 None
Description
Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading to arbitrary code execution in the context of the logged in user. Exploitation of this issue requires a victim to open a malicious file.
Overview
- CVE ID
- CVE-2024-28964
- Assigner
- dell
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-06-12T15:02:53.826Z
- Last Modified Date
- 2024-06-12T16:41:31.838Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://www.dell.com/support/kbdoc/en-us/000224987/dsa-2024-179-security-update-for-dell-emc-common-event-enabler-windows-for-cavatools-vulnerabilities | vendor-advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-28964 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-28964 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 07:31:04 | Added to TrackCVE |