CVE-2019-3735
Summary
| CVE | CVE-2019-3735 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-20 22:15:00 UTC |
| Updated | 2023-03-04 01:52:00 UTC |
| Description | Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management Vulnerability. A malicious local user can exploit this vulnerability by inheriting a system thread using a leaked thread handle to gain system privileges on the affected machine. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Dell | Supportassist For Business Pcs | 2.0 | All | All | All |
| Application | Dell | Supportassist For Business Pcs | 2.0 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 2.2 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 2.2.1 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 2.2.2 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 2.2.3 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 3.0 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 3.0.1 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 3.0.2 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 3.1 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 3.2 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 3.2.1 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 2.2 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 2.2.1 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 2.2.2 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 2.2.3 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 3.0 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 3.0.1 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 3.0.2 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 3.1 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 3.2 | All | All | All |
| Application | Dell | Supportassist For Home Pcs | 3.2.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| DSA-2019-088: Dell SupportAssist Security Update for Improper Privilege Management Vulnerability | Dell US | MISC | www.dell.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Dell would like to thank Bill Demirkapi for reporting this vulnerability.
There are currently no legacy QID mappings associated with this CVE.