CVE-2022-29093: Path Traversal
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files on the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-29093?
CVE-2022-29093 is a vulnerability in Dell SupportAssist Client versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) that allows an authenticated non-admin user to delete arbitrary files on the system.
What is the severity of CVE-2022-29093?
The severity of CVE-2022-29093 is high with a CVSS score of 7.1.
Which software versions are affected by CVE-2022-29093?
Dell SupportAssist for Business PCs versions up to and including 3.1.1 and Dell SupportAssist for Home PCs versions up to and including 3.10.4 are affected by CVE-2022-29093.
How can an authenticated non-admin user exploit CVE-2022-29093?
An authenticated non-admin user can exploit CVE-2022-29093 to delete arbitrary files on the system.
Is there a security update available for CVE-2022-29093?
Yes, Dell has released a security update for CVE-2022-29093. Please refer to the Dell Support website for more information.