Rewterz
Rewterz Threat Alert – Ferocious Kitten APT Group Targeting Iran – Active IOCs
June 21, 2021
Rewterz
Rewterz Threat Alert – New Molerats Malware Targets Governments in the Middle East – Active IOCs
June 21, 2021

Rewterz Threat Advisory – CVE-2021- 21552 – Dell Wyse Windows Embedded System Security Update for an Improper Authorization Vulnerability

Severity

Medium

Analysis Summary

CVE-2021- 21552

Dell Wyse Windows Embedded System versions WIE10 LTSC 2019 and earlier contain an improper authorization vulnerability. An authenticated malicious user with low privileges may potentially exploit this vulnerability to bypass the restricted environment and perform unauthorized actions on the affected system.

Impact

  • Bypass Security
  • Unauthorized Access

Affected Vendors

Dell

Affected Products

  • Dell Wyse 5070 Thin Client
  • Dell Wyse 5470 Thin Client
  • Dell Wyse 5470 All in One Thin Client

Remediation

For the complete list of a?ected products and mitigation techniques refer to the vendor website at

https://www.dell.com/support/home/en-pk/?app=drivers