Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Article Number: 000225779


DSA-2024-263: Security Update for Dell Command| Update, Dell Update, Alienware Update, and Dell SupportAssist for a Path Traversal Vulnerability

Summary: Dell released remediation for a Path Traversal vulnerability in Dell Inventory Collector invoked within Dell Command| Update, Dell Update, Dell Alienware Update, and Dell SupportAssist for PCs (Home and Business) ...

Article Content


Impact

Medium

Details

Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-37129 Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system. 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Proprietary Code CVEs Description CVSS Base Score CVSS Vector String
CVE-2024-37129 Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system. 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:HThis hyperlink is taking you to a website outside of Dell Technologies.
Dell Technologies recommends all customers consider both the CVSS base score and any relevant temporal and environmental scores that may impact the potential severity associated with a particular security vulnerability.

Affected Products and Remediation

Product Affected Versions Remediated Versions Release date (MM/DD/YYYY) Link
Dell Inventory Collector Versions prior to 12.3.0.6 Versions 12.3.0.6 and later 06/24/2024 Drivers and Download FAQs
Product Affected Versions Remediated Versions Release date (MM/DD/YYYY) Link
Dell Inventory Collector Versions prior to 12.3.0.6 Versions 12.3.0.6 and later 06/24/2024 Drivers and Download FAQs
Dell Command Update, Dell Update, Alienware Update, and Dell SupportAssist for PCs (Home and Business) automatically updates Inventory Collector without any user interaction. To verify if you are running the remediated version, follow below steps:
  1. Goto C:\Program Files (x86)\Dell\UpdateService\Service\InvColPC\
  2. Right Click on invcol.exe, click on Properties, then go to Details tab.
  3. Verify Product Version is 12.3.0.6 or later.
  4. If version is not 12.3.0.6 or later,
For SupportAssist,
  1. Windows Search and select SupportAssist
  2. Open SupportAssist
  3. Navigate to “Get Drivers and Downloads” and click on “Run Now”.
   For Dell Command| Update/ Dell Update/ Alienware Update,
  1. Windows Search and select Dell Command| Update/ Dell Update/ Alienware Update
  2. Open Dell Command| Update/ Dell Update/ Alienware Update
  3. Click on “Check”.

Workarounds and Mitigations

None

Acknowledgements

CVE-2024-37129: Dell Technologies would like to thank Jony_Juice for reporting this issue.
 

Revision History

RevisionDateDescription
1.02024-07-30Initial Release
2.02024-07-31Added Revision History Table

Related Information


Article Properties


Affected Product

Alienware Update, SupportAssist, Dell Command | Update, Dell Update

Last Published Date

31 Jul 2024

Article Type

Dell Security Advisory