CVE-2024-53289Time-of-check Time-of-use (TOCTOU) Race Condition in Dell Wyse Proprietary OS

Severity
7.0HIGHNVD
EPSS
0.1%
top 77.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 11

Description

Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages2 packages

NVDdell/thinos2408
CVEListV5dell/wyse_proprietary_osThinOS 2408

🔴Vulnerability Details

1
GHSA
GHSA-wx23-5hwg-8p26: Dell ThinOS version 2408 contains a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability2024-12-11