CVE-2023-43078

Privilege escalation via installation link resolution

Published Aug 28, 2024 · Updated Aug 28, 2024

Improper link resolution in Dell client BIOS firmware before model-specific fixes allows local users to delete arbitrary folders during installation. Dell has not disclosed the affected installer component or the exact link-handling operation that redirects deletion to an unintended folder. Exploitation requires local low-privileged access and user interaction; successful abuse can elevate privileges or interrupt the system by deleting required folders.

CVSS severity6.7
Medium
EPSS probability0.17%
Next 30 days · Sep 16, 2026
Known exploitationUnconfirmed
Based on sourced intelligence
Hinoki checkNot available
Coverage for this vulnerability

See if you're affected

Explore vulnerability checks for your environment with Hinoki.

Book a demo

Summary

What happened

Improper link resolution in Dell client BIOS firmware before model-specific fixes allows local users to delete arbitrary folders during installation. Dell has not disclosed the affected installer component or the exact link-handling operation that redirects deletion to an unintended folder. Exploitation requires local low-privileged access and user interaction; successful abuse can elevate privileges or interrupt the system by deleting required folders.

The record

CVE
CVE-2023-43078
Published
Aug 28, 2024
Updated
Aug 28, 2024
Vendor
Dell
Product
Alienware m15 R6 Firmware
Classifications
CWE-59
Attack vector
local
Privileges
authenticated

Timeline

How it unfolded

  1. Aug 28, 2024CVE publishedPublication date reported by the CVE source.
  2. Aug 28, 2024Record updatedLatest update available in the CVE record.

Exploitability

Present is not the same as exploitable

Compare your product and version with the public record. A matching version still requires validation against your environment.

Is a vulnerable build present?

Compare these published version ranges with your installed build and any vendor patches.

  1. Affected versionversion=0 <1.27.0

What conditions does exploitation require?

Attack vectorlocal
Required privilegesauthenticated

What is affected?

Dell · Alienware m15 R6 Firmwareversion=0 <1.27.0
Dell · Dell G15 5530 Firmwareversion=0 <1.12.0
Dell · Inspiron 13 5320 Firmwareversion=0 <1.16.0
Dell Technologies · Precision 3630 Towerversion=0 <2.25.0
Dell · Dell Latitude 9520 Firmwareversion=0 <1.30.1
Dell · Chengming 3900 Firmwareversion=0 <1.19.0
Dell · Chengming 3988 Firmwareversion=0 <1.20.0
Dell Technologies · Precision 3650 Towerversion=0 <1.28.1
Dell · Inspiron 24 5411 All-in-One Firmwareversion=0 <1.18.0
Dell · Dell Inspiron 3891 Firmwareversion=0 <1.22.1
Dell · Dell OptiPlex 3090 Firmwareversion=0 <2.16.0
Dell · Dell Latitude 5420 Firmwareversion=0 <1.36.2
Dell · Dell Latitude 7220 Rugged Extreme Firmwareversion=0 <1.33.0
Dell · Dell Latitude 7290 Firmwareversion=0 <1.35.0
Dell · Dell Latitude 3340 Firmwareversion=0 <1.10.0
Dell · Dell Latitude 5290 Firmwareversion=0 <1.32.0
Dell · Dell G15 5511 Firmwareversion=0 <1.26.0
Dell · Dell Inspiron 5301 Firmwareversion=0 <1.31.0
Dell · Alienware x14 R2 Firmwareversion=0 <1.11.0
Dell Technologies · Precision 3260 XE Compactversion=0 <3.3.2
Dell · Dell OptiPlex 5090 Tower Firmwareversion=0 <1.22.2
Dell · Dell G3 3500 Firmwareversion=0 <1.28.0
Dell · Dell OptiPlex 3000 Thin Client Firmwareversion=0 <1.15.0
Dell · Inspiron 3593 Firmwareversion=0 <1.29.0
Dell · Inspiron 14 5410 Firmwareversion=0 <2.24.0
Dell · Dell G5 5000 Firmwareversion=0 <1.17.0
Dell · Dell OptiPlex 3080 Firmwareversion=0 <2.22.0
Dell · Dell Latitude 5530 Firmwareversion=0 <1.21.1
Dell · Inspiron 3880 Firmwareversion=0 <1.24.1
Dell · Dell G7 7700 Firmwareversion=0 <1.30.0
Dell · Dell Latitude 5320 Firmwareversion=0 <1.36.0
Dell · Alienware m16 R1 Firmwareversion=0 <1.14.1
Dell · Dell G5 5090 Firmwareversion=0 <1.23.0
Dell · Inspiron 15 3530 Firmwareversion=0 <1.8.0
Dell · Dell Latitude 3420 Firmwareversion=0 <1.34.0
Dell · Dell Latitude 5340 Firmwareversion=0 <1.10.1
Dell · Alienware m15 R7 Firmwareversion=0 <1.22.0
Dell · Chengming 3991 Firmwareversion=0 <1.24.0
Dell · Inspiron 13 5330 Firmwareversion=0 <1.12.1
Dell · Dell Latitude 3300 Firmwareversion=0 <1.25.0
Dell · Dell OptiPlex 5400 All-in-One Firmwareversion=0 <1.1.37
Dell · Dell Latitude 7320 Firmwareversion=0 <1.34.2
Dell · Dell OptiPlex 5490 All-in-One Firmwareversion=0 <1.27.1
Dell Technologies · Precision 3660 Towerversion=0 <2.11.1

Published CVSS scores

7.3NVDCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
6.7DellCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CVSS describes severity. EPSS estimates exploitation probability.

Attacks

What attackers are doing with it

Daily unique IPs observed by Shadowserver honeypots for known exploited vulnerabilities (KEVs). Missing observations do not establish an absence of attacks.

Daily unique IPsNo honeypot observations are available for this CVE in the selected window.

No observations available

Sep 10, 2026Sep 16, 2026
Latest reporting daySep 16, 2026
Latest daily unique IPsUnavailable
Prior 30-day averageUnavailable
SourceShadowserver honeypots (KEV)
Vectorlocal
Privilegesauthenticated
Known exploitationUnconfirmed
Public exploitUnconfirmed

Weakness, pattern, technique

CWE-59Improper Link Resolution Before File Access ('Link Following')

Public exploit references

No public exploit references are available in this record.

Labels summarize the accepted research assessment. They do not indicate a test against your environment.

Technologies

Your stack

See the directory against your own environment.

Your stack

Check the software in your environment

Book a demo to see how Hinoki identifies affected software and validates exploitability in your environment.

Book a demo