Pc-Doctor: Dell has disclosed a new vulnerability affecting Dell SupportAssist pre-loaded software. The flaw, discovered by SafeBreach and analyzed in detail by security researcher Peleg Hadar, reveals a high-level breach that would allow any hacker with remote access to root-level DLLs and inject malicious code at the deep system level to take over a system and gain access to the storage of a laptop or desktop computer.

The vulnerability is designated CVE-2019-12280 and affects Dell SupportAssist software v2.0for business PCs and v3.2.1 for personal devices.
After remotely injecting malicious DLLs into the system, attackers could take advantage of system-level DLLs that have full access to a computer. While SafeBreach did not disclose whether the issue has been exploited, it did say that the vulnerability affects devices other than those owned by Dell.
But why should other devices besides Dell be affected?;

The reason is that the firmware is manufactured by PC-Doctor, which creates and maintains system maintenance software for many OEMs. As a result, the actual number of affected devices could be much higher and would range around 100 million laptops and desktops worldwide. This means that any service that uses the PC-Doctor software with deep-level system access has this vulnerability and, considering its criticality, should release an update soon.
It is important to note that Dell recently faced a similar vulnerability with its SupportAssist, which allowed hackers to remotely take over a system and gain root-level access. This, in turn, could allow ransomware and other malicious code to be introduced. Given that Dell is one of the largest OEMs for laptops and PCs, the risk could be enormous.
