HomeinetDell: update your computers immediately

Dell: update your computers immediately

Dell has released a security update to address a vulnerability in its support software (SupportAssist Client). SupportAssist allows unauthenticated users from the same Network Access layer to remotely run malicious executables on vulnerable computers.

Dell

According to the company's website, SupportAssist software is "pre-installed on most new Dell devices running the Windows operating system" and "actively monitors the health of the system's hardware and software. When it discovers an issue, it sends it to Dell to begin troubleshooting."

Most new Dell computers are vulnerable to RCE (Remote code execution) attacks.

The software flaw has been reported as CVE-2019-3719 and has been published at a high severity level (CVSSv3) reaching 8.0 by the National Vulnerability Database (NVD).

Dell updated its SupportAssist software in late April 2019 after an initial report received from a 17-year-old security researcher (Bill Demirkapi) on October 10, 2018.

Dell advises all its customers to update SupportAssist Client as soon as possible, stating that all versions prior to 3.2.0.90 are vulnerable to remote code execution attacks.

Dell has also reportedly fixed an improper origin validation flaw in the SupportAssist Client software reported by John C. Hennessy-ReCar, which has been reported as CVE-2019-3718 with a high severity (CVSS v3.0) rating of 8.8.

Security researcher Bill Demirkapi discovered that the RCE vulnerability can be exploited by attackers using ARP and DNS spoofing attacks, as he details in the proof-of-concept he published.

Watch the demo video on YouTube showing its PoC

_________________

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS