Vulnerability Description
Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software installs multiple services incorrectly by specifying the paths to the service executables without quotes. This could potentially allow a low-privileged local user to execute arbitrary executables with elevated privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dell | Wyse Management Suite | <= 1.1 |
Related Weaknesses (CWE)
References
- https://www.dell.com/support/article/us/en/19/sln313398/dell-wyse-management-suiVendor Advisory
- https://www.dell.com/support/article/us/en/19/sln313398/dell-wyse-management-suiVendor Advisory
FAQ
What is CVE-2018-11063?
CVE-2018-11063 is a vulnerability with a CVSS score of 7.8 (HIGH). Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software installs multiple services incorrectly by specifying the paths to the service executab...
How severe is CVE-2018-11063?
CVE-2018-11063 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11063?
Check the references section above for vendor advisories and patch information. Affected products include: Dell Wyse Management Suite.