First published: Fri Dec 22 2023(Updated: )
Dell SupportAssist for Home PCs version 3.14.1 and prior versions contain a privilege escalation vulnerability in the installer. A local low privileged authenticated attacker may potentially exploit this vulnerability, leading to the execution of arbitrary executable on the operating system with elevated privileges.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell SupportAssist for Home PCs | =3.14.2.45116 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-48670 is a privilege escalation vulnerability that allows low privileged authenticated attackers to execute arbitrary code.
To mitigate CVE-2023-48670, update Dell SupportAssist for Home PCs to version 3.14.2.45116 or later.
CVE-2023-48670 affects users of Dell SupportAssist for Home PCs version 3.14.1 and earlier.
CVE-2023-48670 allows local attackers to escalate privileges and execute arbitrary executables on the system.
Exploiting CVE-2023-48670 requires local access and authenticated privileges, making it more challenging for remote attackers.