CVE-2020-5316: High severity dell supportassist vulnerability
Dell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home PCs version 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, 3.2.1, 3.2.2, 3.3, 3.3.1, 3.3.2, 3.3.3, 3.4 contain an uncontrolled search path vulnerability. A locally authenticated low privileged user could exploit this vulnerability to cause the loading of arbitrary DLLs by the SupportAssist binaries, resulting in the privileged execution of arbitrary code.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Dell SupportAssist vulnerability?
The vulnerability ID for this Dell SupportAssist vulnerability is CVE-2020-5316.
What is the severity of CVE-2020-5316?
The severity of CVE-2020-5316 is high (7.8).
Which software versions are affected by CVE-2020-5316?
Dell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, 3.2.1, 3.2.2, 3.3, 3.3.1, 3.3.2, 3.3.3, 3.4 are affected by CVE-2020-5316.
How can I fix CVE-2020-5316?
To fix CVE-2020-5316, Dell has released a security advisory and patch, which you can find at the following link: http://www.dell.com/support/article/SLN320101
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-5316?
The Common Weakness Enumeration (CWE) ID for CVE-2020-5316 is 427.