CVE-2024-22451
Description
Dell Peripheral Manager, versions from 1.5.1 to 1.7.2, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious executable, leading to arbitrary code execution.
Summary dbcve.org
Dell Peripheral Manager versions 1.5.1 through 1.7.2 contain an uncontrolled search path element vulnerability that allows DLL/executable preloading. By placing a malicious executable in a directory that gets searched before the legitimate path, an attacker can achieve arbitrary code execution when the application launches.
Mitigation
Update Dell Peripheral Manager to a version beyond 1.7.2 once available. Until then, ensure the application runs from trusted directories with restricted write permissions and avoid launching from user-writable locations such as downloads or temp folders.