First published: Wed Dec 25 2024(Updated: )
Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell SupportAssist | <4.6.1 | |
Dell SupportAssist | <4.5.0 | |
Dell SupportAssist | <4.5.1 | |
Dell SupportAssist | <4.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-52535 has been rated as a low severity vulnerability.
To mitigate CVE-2024-52535, update Dell SupportAssist for Home PCs to version 4.6.2 or later and for Business PCs to version 4.5.1 or later.
CVE-2024-52535 affects users of Dell SupportAssist for Home PCs version 4.6.1 and earlier and Dell SupportAssist for Business PCs version 4.5.0 and earlier.
CVE-2024-52535 requires a low-privileged authenticated user to exploit the vulnerability.
CVE-2024-52535 is a symbolic link (symlink) attack vulnerability found in the software remediation component of Dell SupportAssist.