VYPR

DUP framework

by Dell

CVEs (2)

  • CVE-2023-39254MedMar 1, 2024
    risk 0.44cvss 6.7epss 0.00

    Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially exploit this vulnerability to run arbitrary code as admin.

  • CVE-2023-32454MedFeb 6, 2024
    risk 0.41cvss 6.3epss 0.00

    DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create arbitrary files, leading to denial of service