CVE-2021-36297: High severity dell supportassist vulnerability
SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation for executing arbitrary dll's,
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-36297?
CVE-2021-36297 is a vulnerability found in SupportAssist Client version 3.8 and 3.9 that allows attackers to load an arbitrary .dll file via .dll planting/hijacking.
How can an attacker exploit CVE-2021-36297?
An attacker can exploit CVE-2021-36297 by performing a separate administrative action that is not part of the default installation process of SOSInstallerTool.exe.
What is the severity of CVE-2021-36297?
CVE-2021-36297 has a severity rating of 7.8 (high).
Which software versions are affected by CVE-2021-36297?
SupportAssist Client versions 3.8 and 3.9 are affected by CVE-2021-36297.
How can I mitigate the vulnerability CVE-2021-36297?
To mitigate CVE-2021-36297, it is recommended to apply the security update provided by Dell as mentioned in the reference link.