CVE-2022-34366: Medium severity dell supportassist vulnerability
Published Feb 10, 2023
·Updated
Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.
Affected Software
1 affected component
Dell SupportAssist for Home PCs<=3.11.2
Event History
Feb 10, 2023
CVE Published
via MITRE·07:18 PM
Data Sourced
via MITRE·07:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-34366?
CVE-2022-34366 is a vulnerability in Dell SupportAssist for Home PCs (version 3.11.2 and prior) that allows an authenticated non-admin user to obtain sensitive information.
2
How severe is CVE-2022-34366?
CVE-2022-34366 has a severity score of 6.5, which is considered medium.
3
How can an attacker exploit CVE-2022-34366?
An authenticated non-admin user can exploit CVE-2022-34366 to obtain sensitive information.
4
What software versions are affected by CVE-2022-34366?
Dell SupportAssist for Home PCs version 3.11.2 and prior are affected by CVE-2022-34366.
5
How can I fix CVE-2022-34366?
To fix CVE-2022-34366, Dell recommends updating to the latest version of SupportAssist for Home PCs.