A critical vulnerability has been discovered in Dell's client platform BIOS, which could allow arbitrary code execution by hackers.

This flaw , known as CVE-2024-39584, is classified as a “Default Encryption Key Usage” vulnerability. It is a significant threat, with a CVSS score of 8.2, indicating a high impact on the affected systems.
Specifically, the vulnerability allows hackers with high privileges to bypass secure boot and execute arbitrary code on affected systems.
Read also: Dell: Calls for employees to return to the office, otherwise...otherwise what?
The vulnerability notice specifically states: "Dell client platform BIOS recovery is available for a vulnerability related to the use of the default encryption, which could be exploited by hackers, compromising the affected system."
Products that are affected and their remediation process.
Dell has released updates to address this vulnerability. The affected products and their corresponding BIOS versions are as follows:
- Alienware Area 51m R2: Earlier releases of 1.29.0
- Alienware Aurora R15 AMD: Earlier releases of 1.15.0
- Alienware m15 R3: Earlier releases of 1.29.0
- Alienware m15 R4: Earlier releases of 1.24.0
- Alienware m17 R3: Earlier releases of 1.29.0
- Alienware m17 R4: Earlier releases of 1.24.0
- Alienware x14: Earlier releases of 1.21.0
- Alienware x15 R1: Earlier releases of 1.24.0
- Alienware x15 R2: Earlier releases of 1.22.0
- Alienware x17 R1: Earlier releases of 1.24.0
- Alienware x17 R2: Earlier releases of 1.22.0
Dell has advised users to update their BIOS with the new releases that were launched on August 27 and 28, 2024, in order to protect themselves from potential exploits. Users can find these updates on the Dell Drivers & Downloads website.
There are currently no workarounds or mitigations for vulnerability . Users are strongly advised to apply BIOS updates as soon as possible to ensure the security of their systems.
See also: Dell customer data breached

Dell Technologies acknowledges the efforts of the BINARLY research team in discovering and reporting this serious issue. The company emphasizes the importance of regular updates to protect against potential threats.
For more information, users are urged to visit security and ensure their systems are up to date with the latest security patches.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
