First published: Thu Jun 09 2022(Updated: )
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticated non-admin user could exploit the issue and delete or overwrite arbitrary files on the system.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell SupportAssist for Business PCs | <=3.1.1 | |
Dell SupportAssist for Home PCs | <=3.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29094 is a vulnerability found in Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior), allowing an authenticated non-admin user to delete or overwrite arbitrary files.
CVE-2022-29094 is classified as a high severity vulnerability with a CVSS severity score of 7.1.
An authenticated non-admin user can exploit CVE-2022-29094 by deleting or overwriting arbitrary files.
Dell SupportAssist Client Consumer versions 3.10.4 and versions prior are affected by CVE-2022-29094.
Dell SupportAssist Client Commercial versions 3.1.1 and versions prior are affected by CVE-2022-29094.
To fix CVE-2022-29094, update Dell SupportAssist Client Consumer to version 3.10.5 or later, and Dell SupportAssist Client Commercial to version 3.1.2 or later.