A severe security flaw, designated CVE-2024-49600, has been discovered in Dell Power Manager (DPM), a widely used software utility for controlling power configurations on Dell computer systems. Versions earlier than 3.17 are impacted and result from improper access control, which enables attackers who have low-level privileges and are locally logged in to run arbitrary code and elevate their privileges. The vulnerability is rated as high security threat and has been given a CVSS base score of 7.8, which reflects high potential for impact on confidentiality, integrity, and availability. As of the CVSS vector (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), the vulnerability is only accessible by local access, has simple attack complexity, and does not require user interaction—making the exploit simpler for attackers. After being exploited, an attacker might be able to take complete control of the compromised system. Dell Technologies has made version 3.17 of Dell Power Manager available on December 5, 2024, which mitigates and remediates the flaw. All users of previous versions are highly encouraged to update as soon as possible. No time-limited workarounds or mitigations exist, and patching is the only viable solution in a timely manner. Organizations must give top priority to the update and apply strict access control and strong endpoint protection in order to minimize risks of exploitation. Dell thanks TsungShu Chiu of CHT Security for reporting and finding the issue. Customers are requested to consider the CVSS score based on their own environments and contact Dell's official support in case of requirements. The incident serves to underscore the continuing relevance of frequent software updates and aggressive cybersecurity measures.
The researchers uncovered an attack that released 175 malicious npm packages. The packages had been downloaded approximately 26,000 times and were utilized to steal login credentia...
A recently found Python-based Remote Access Trojan (RAT) having the SHA256 hash 7173e20e7ec217f6a1591f1fc9be6d0a4496d78615cc5ccdf7b9a3a37e3ecc3c on VirusTotal exhibits sophisticate...
A security researcher has found a critical flaw in the popular Worldline Yomani XR payment terminal, which could enable attackers to take complete control over the terminal within ...