← Vulnerability feed

Vulnerability record · CVE-2022-34384 · published 11 February 2023

CVE-2022-34384: Dell alienware update execution with unnecessary privileges vulnerability

Dell · Alienware Update

Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may potentially exploit this vulnerability, leading to privilege escalation.

7.8 CVSS 3.1 High EPSS 0.23% · top 87.3% CWE-250 · Execution with unnecessary privilegesCWE-269 · Improper privilege management
7.8CVSS 3.1 base score
0.23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may potentially exploit this vulnerability, leading to privilege escalation.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-34384 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.6CVE-2022-29095Dell supportassist for business pcs cross-site scripting vulnerabilityDell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-si…EPSS 1.2%8.8CVE-2026-58565Dell command update missing authorization vulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could …EPSS 0.14%8.8CVE-2024-52535Dell supportassist for business pcs link following vulnerabilityDell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (s…EPSS 0.55%7.8CVE-2026-58564Dell command update incorrect default permissions vulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local acce…EPSS 0.14%7.8CVE-2026-53477Dell command update toctou race condition vulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attac…EPSS 0.12%7.8CVE-2026-49816Dell command update deserialization of untrusted data vulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local a…EPSS 0.31%7.8CVE-2026-49817Dell command update deserialization of untrusted data vulnerabilityDell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local a…EPSS 0.31%7.8CVE-2025-36612Dell supportassist for business pcs vulnerabilitySupportAssist for Business PCs, version(s) 4.5.3 and prior, contain(s) an Incorrect Privilege Assignment vulnerability. A low privileged attacker wit…EPSS 0.10%

Source: NIST National Vulnerability Database (record CVE-2022-34384), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.