Database/Control plane, storage & DevOps
Dell OpenManage Server Administrator (XSL hijacking local privilege escalation): A local low-privileged user hijacks
CVE-2024-37130Control plane, storage & DevOpscurated
Impact
A local low-privileged user hijacks an XSL load path and escalates to admin, gaining full control of the machine.
Who can reach it
Local low-privilege user on a host running OMSA 11.0.1.0 or earlier.
What to do
Upgrade OMSA past 11.0.1.0. Agent update on every host that runs it.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.