Dell announced on June 21 that it has released a critical update for its Dell SupportAssist software – which is likely present on your Dell computer if you didn't promptly remove the pre-installed junk.
Specifically, SupportAssist's PC-Doctor has a vulnerability in the way it checks (or doesn't check) the validity of certain DLLs on your computer.
If someone manages to sneak a malicious DLL onto your machine, in a specific location and with a specific file name, PC-Doctor runs it with system-level privileges.

According to the company, the Dell SupportAssist for Business PC application in version 2.0.1 and the Dell SupportAssist for Home PC application in version 3.2.2 are the builds you should install immediately to protect your computers.
The company has this specific troubleshooting program with every new desktop, laptop and tablet.
Security firm SafeBreach Labs was the first to discover the flaw, and initially reported to Dell that SupportAssist could run DLLs at the SYSTEM level.
This means that if a malicious application leaves a .dll file of its own somewhere on the disk, it just has to wait to "meet" SupportAssist.
Of course, those of you who have a Dell computer and have not updated your system, you should do so immediately.
"We can assume that all Dell computers running the Windows operating system without changes from the manufacturer are vulnerable," SafeBreach Labs says.
But what's more worrying is that the security firm believes that Dell is not the only company that has software with this particular flaw.
The reason for this is that the vulnerability is in a third-party component of Dell's SupportAssist software, which is developed and maintained by PC Doctor, a support and diagnostics application company:
PC Doctor sells its software to computer manufacturers who then integrate it into their products, such as SupportAssist in the case of Dell.
You may recall that the same Dell SupportAssist had another security flaw in May 2019.
Of course, at iGuRu.gr, we have mentioned many times that you do not need to continue using this type of crapware, so an alternative to updating is to uninstall the application.
________________
- YTS new .LT Domain, visible in Greece without DNS change
- Facebook Libra: Three questions for Facebook
- Florida pays $600,000 ransom to ransomware
