Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.
Some article numbers may have changed. If this isn't what you're looking for, try searching all articles. Search articles

Article Number: 000197723


DSA-2022-074: Dell Command | Update and Dell Update, and Alienware Update Security Update for a Local Privilege Escalation Vulnerability

Summary: Dell Command | Update and Dell Update, and Alienware Update remediation is available for a Local Privilege Escalation Vulnerability that may be exploited by malicious users to compromise the affected system. ...

Article Content


Impact

High

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2022-24426 Dell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may potentially exploit this vulnerability, leading to privilege escalation. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2022-24426 Dell Command | Update, Dell Update, and Alienware Update version 4.4.0 contains a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may potentially exploit this vulnerability, leading to privilege escalation. 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Product Affected Versions Updated Versions Link to Update
Dell Command | Update
 
4.4.0
 
4.5.0
 
Universal Windows Platform version for Windows 10, 32 and 64 bit
Dell Command | Update Application for Windows 10 | Driver Details | Dell US
Windows 32 and 64-bit version for Microsoft Windows 7, 8, 8.1, and 10
Dell Command | Update Application | Driver Details | Dell US
Dell Update and
Alienware Update
4.4.0
 
4.5.0
 
Universal Windows Platform version for Windows 10, 32 and 64 bit
Dell Update/Alienware Update Application for Windows 10 | Driver Details | Dell US
Windows 32 and 64-bit version for Microsoft Windows 7, 8, 8.1, and 10
Dell Update/Alienware Update Application | Driver Details | Dell US
Product Affected Versions Updated Versions Link to Update
Dell Command | Update
 
4.4.0
 
4.5.0
 
Universal Windows Platform version for Windows 10, 32 and 64 bit
Dell Command | Update Application for Windows 10 | Driver Details | Dell US
Windows 32 and 64-bit version for Microsoft Windows 7, 8, 8.1, and 10
Dell Command | Update Application | Driver Details | Dell US
Dell Update and
Alienware Update
4.4.0
 
4.5.0
 
Universal Windows Platform version for Windows 10, 32 and 64 bit
Dell Update/Alienware Update Application for Windows 10 | Driver Details | Dell US
Windows 32 and 64-bit version for Microsoft Windows 7, 8, 8.1, and 10
Dell Update/Alienware Update Application | Driver Details | Dell US

Acknowledgements

Dell would like to thank Alexander Pudwill for reporting this issue.
 

Revision History

RevisionDateDescription
1.02022-03-25Initial Release
1.12022-05-20CVE Description correction: only version 4.4.0 is affected

Related Information


Article Properties


Affected Product

Alienware Update, Dell Command | Update, Dell Update, Product Security Information

Last Published Date

24 May 2022

Article Type

Dell Security Advisory