First published: Thu Jul 22 2021(Updated: )
Dell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home PCs version 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, 3.2.1, 3.2.2, 3.3, 3.3.1, 3.3.2, 3.3.3, 3.4 contain an uncontrolled search path vulnerability. A locally authenticated low privileged user could exploit this vulnerability to cause the loading of arbitrary DLLs by the SupportAssist binaries, resulting in the privileged execution of arbitrary code.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell SupportAssist for Business PCs | =2.0 | |
Dell SupportAssist for Business PCs | =2.0.1 | |
Dell SupportAssist for Business PCs | =2.0.2 | |
Dell SupportAssist for Business PCs | =2.1 | |
Dell SupportAssist for Business PCs | =2.1.1 | |
Dell SupportAssist for Business PCs | =2.1.2 | |
Dell SupportAssist for Business PCs | =2.1.3 | |
Dell SupportAssist for Home PCs | =2.0 | |
Dell SupportAssist for Home PCs | =2.0.1 | |
Dell SupportAssist for Home PCs | =2.0.2 | |
Dell SupportAssist for Home PCs | =2.1 | |
Dell SupportAssist for Home PCs | =2.1.1 | |
Dell SupportAssist for Home PCs | =2.1.2 | |
Dell SupportAssist for Home PCs | =2.1.3 | |
Dell SupportAssist for Home PCs | =2.2 | |
Dell SupportAssist for Home PCs | =2.2.1 | |
Dell SupportAssist for Home PCs | =2.2.2 | |
Dell SupportAssist for Home PCs | =2.2.3 | |
Dell SupportAssist for Home PCs | =3.0 | |
Dell SupportAssist for Home PCs | =3.0.1 | |
Dell SupportAssist for Home PCs | =3.0.2 | |
Dell SupportAssist for Home PCs | =3.1 | |
Dell SupportAssist for Home PCs | =3.2 | |
Dell SupportAssist for Home PCs | =3.2.1 | |
Dell SupportAssist for Home PCs | =3.2.2 | |
Dell SupportAssist for Home PCs | =3.3 | |
Dell SupportAssist for Home PCs | =3.3.1 | |
Dell SupportAssist for Home PCs | =3.3.2 | |
Dell SupportAssist for Home PCs | =3.3.3 | |
Dell SupportAssist for Home PCs | =3.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Dell SupportAssist vulnerability is CVE-2020-5316.
The severity of CVE-2020-5316 is high (7.8).
Dell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, 3.2.1, 3.2.2, 3.3, 3.3.1, 3.3.2, 3.3.3, 3.4 are affected by CVE-2020-5316.
To fix CVE-2020-5316, Dell has released a security advisory and patch, which you can find at the following link: http://www.dell.com/support/article/SLN320101
The Common Weakness Enumeration (CWE) ID for CVE-2020-5316 is 427.