First published: Fri Jun 10 2022(Updated: )
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files on the system.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell SupportAssist for Business PCs | <=3.1.1 | |
Dell SupportAssist for Home PCs | <=3.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29093 is a vulnerability in Dell SupportAssist Client versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) that allows an authenticated non-admin user to delete arbitrary files on the system.
The severity of CVE-2022-29093 is high with a CVSS score of 7.1.
Dell SupportAssist for Business PCs versions up to and including 3.1.1 and Dell SupportAssist for Home PCs versions up to and including 3.10.4 are affected by CVE-2022-29093.
An authenticated non-admin user can exploit CVE-2022-29093 to delete arbitrary files on the system.
Yes, Dell has released a security update for CVE-2022-29093. Please refer to the Dell Support website for more information.