HomeSecurityDell: Its new update will fix a bug in Dell SupportAssist

Dell: Its new update will fix a bug in Dell SupportAssist

Dell - software updateDell has released a security update to fix a flaw in its SupportAssist Client software that could allow potential local hackers to execute arbitrary code with Administrator privileges on vulnerable computers. According to Dell’s website, SupportAssist software is pre-installed on most new Dell devices running Windows. SupportAssist also proactively checks the “health” of a system’s hardware and software. When a problem is detected, system health information is sent to Dell to begin troubleshooting.

As Dell explained, a hacker could exploit this flaw to cause arbitrary DLLs to be loaded from SupportAssist support files, resulting in “privileged” execution of arbitrary code. This search path flaw, tracked as CVE-2020-5316, comes with a high CVSSv3 base severity score of 7.8 and affects the following versions of Dell SupportAssist:

  • Dell SupportAssist for Business PCs version 2.1.3 or earlier.
  • Dell SupportAssist for Home PCs version 3.4 or earlier.

The company has released Dell SupportAssist version 2.1.4 for business PCs and Dell SupportAssist version 3.4.1 for home PCs with fixes for the flaw. Since all unpatched versions are vulnerable to attacks, the company advises all customers to update the Dell SupportAssist software on their PCs as soon as possible. If a hacker exploits this flaw, they would be able to load and execute malicious payloads within the SupportAssist binaries on unpatched devices. While the threat level of this flaw is not obvious, given that it requires local access and a low-privileged user on the system to be compromised, such security issues – some of which also require Administrator privileges – are routinely rated with a high CVSS 3.x severity score (1.2).Dell supportassist update software Dell: Its new update will fix a bug in Dell SupportAssist

The company says that all versions of SupportAssist will automatically install the latest updates that are released if automatic updates are enabled. If automatic updates are not enabled, home customers can manually check for updates by opening the SupportAssist software and clicking 'About SupportAssist' in the Settings window to check for newer versions, and then the 'Update Now' link will appear.

For business customers, the process is a bit more complicated, and Dell recommends following the Dell SupportAssist for Business PCs instructions. The company patched a code execution flaw in its SupportAssist Client software in May 2019 that allowed unauthenticated hackers to attack at the same level of network access and remotely perform arbitrary actions on vulnerable devices. A similar RCE flaw was found by security researcher Tom Forbes in Dell System Detect software in 2015. Forbes said at the time that the flaw allowed a hacker to trigger the program to download and execute an arbitrary file without user interaction.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS