CVE-2024-28964: Dell Common Event Enabler
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Dell Common Event Enabler, version 8.9.10.0 and prior, contain an insecure deserialization vulnerability in CAVATools. A local unauthenticated attacker could potentially exploit this vulnerability, leading to arbitrary code execution in the context of the logged in user. Exploitation of this issue requires a victim to open a malicious file.
Affected products
- Dell Common Event Enabler: up to and including 8.9.10.0
Published 2024-06-12. Last modified 2026-06-17.