A 17-year-old security researcher, Bill Demirkapi, is warning all Dell desktop and laptop owners, as he discovered a vulnerability in Dell SupportAssist. The vulnerability allows hackers to hack into the computer system, remotely executing malicious code. It does this by forcing the user to visit a malicious website.
Specifically, hackers can use the vulnerability CVE-2019-3719 and execute malicious code with administrator privileges. The vulnerable devices are those using an older version of the Dell SupportAssist tool. By exploiting the error, hackers can take control of the victim's system
The attack works as follows: Attackers trick users into visiting a specific website. The site contains JavaScript code that tricks the SupportAssist application into downloading and running malicious files (with full administrator privileges).
The most worrying thing is that just visiting the site is enough to install the malicious JavaScript. The user does not need to do anything else. The JavaScript can be hidden inside an ad and starts running automatically.
The job of Dell's SupportAssist tool is the preventive checking of hardware and software and the automatic updating of the system when needed.
Usually the software is preinstalled on new Dell devices, resulting in many users with vulnerable systems.
Dell is aware of the security and has already released a SupportAssist patch (v3.2.0.90) to address it. Therefore, people who have SupportAssist installed on their Dell laptop or desktop should download and install the update to protect their systems.
