HomeinetSecurity vulnerabilities discovered in Dell preinstalled software

Security vulnerabilities discovered in Dell pre-installed software

Dell device customers may be exposed to cyber attacks, as the pre-installed software contains vulnerabilities that could allow a hacker to disable security solutions.

Dell

Marcin ‘Icewall’ Noga of Cisco Talos has discovered 3 distinct vulnerabilities affecting selected Dell systems, urging customers to install the latest updates as soon as possible to prevent attacks.

First of all, there is a privilege vulnerability documented in CVE-2016-9038, which also exists in the SboxDrv.sys driver. The researcher notes that the security flaw can be exploited by sending crafted data to \Device\SandboxDriverApi device driver because it provides read and write permissions to everyone. A successful exploit could lead to local privilege escalation, the researcher notes, adding that Invincea-X and Dell Protected Workspace 6.1.3-24058 are both vulnerable.

Next, CVE-2016-8732, which is an attempt to bypass a vulnerability. This time the vulnerable software is Dell Protected Workspace 5.1.1-22303, whose InvProtectDrv.sys driver file contains multiple vulnerabilities.

«Due to the low restriction regarding the driver’s communication channel, as well as due to insufficient validation, an intrusion could check the application running on a vulnerable system and could exploit this system to effectively disable some of the protection mechanisms provided by the software» the security report states.

The Dell Protected Workspace solution is primarily aimed at businesses, so  IT professionals and CIOs should hurry to install version 6.3.0 of the software, which is said to fix the vulnerability.

And one final but no less important point, CVE-2017-2802 describes another protection vulnerability bypass, this time affecting the Dell PPO Service which is part of the Dell Precision Optimizer application. The issue has been fixed in version 4.0 of the application.

It is obvious that customers must install all available updates as soon as possible, although for now Dell does not know the existence of exploits based on these vulnerabilities.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS