Vulnerabilities > CVE-2024-28964 - Deserialization of Untrusted Data vulnerability in Dell Common Event Enabler 8.9.10.0/8.9.8.2

047910
CVSS 7.8 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
local
low complexity
dell
CWE-502

Summary

Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading to arbitrary code execution in the context of the logged in user. Exploitation of this issue requires a victim to open a malicious file.

Vulnerable Configurations

Part Description Count
Application
Dell
3

Common Weakness Enumeration (CWE)