First published: Thu Apr 18 2019(Updated: )
Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compromise the vulnerable system by tricking a victim user into downloading and executing arbitrary executables via SupportAssist client from attacker hosted sites.
Credit: security_alert@emc.com security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell SupportAssist | <3.2.0.90 | |
<3.2.0.90 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3719 is classified as a critical vulnerability due to its potential for remote code execution.
To fix CVE-2019-3719, update Dell SupportAssist Client to version 3.2.0.90 or later.
CVE-2019-3719 affects Dell SupportAssist Client versions prior to 3.2.0.90.
CVE-2019-3719 allows unauthenticated remote code execution by an attacker on the same network.
The primary risk of CVE-2019-3719 is that an attacker can execute arbitrary code on a vulnerable system.