QID 376023
Date Published: 2021-11-11
QID 376023: Dell SupportAssist arbitrary file deletion Vulnerability (DSA-2021-163)
Dell SupportAssist automatically detects and proactively alerts for operating system issues, software upgrades, driver updates.
Dell SupportAssist for Business PCs require an update to the latest versions to address a security vulnerability within the PC Doctor component.
Affected Versions:
Dell SupportAssist for Home PCs Version 3.9 and earlier
Dell SupportAssist for Business PCs Versions 2.4.1 and earlier
QID Detection Logic(Authenticated):
This QID checks for vulnerable version of Dell SupportAssist.
May allow nonprivileged users to create junction points and delete arbitrary files on the system which can be accessed only by the admin.
Solution
Customers are advised to Customers are advised to download Dell SupportAssist for Business PCs version 3.0.0 and Dell SupportAssist for Home PCs version 3.10 to fix these vulnerabilities
For more information please visit here.
For more information please visit here.
Vendor References
CVEs related to QID 376023
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| DSA-2021-163 |
|