Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compromise the vulnerable system by tricking a victim user into downloading and executing arbitrary executables via SupportAssist client from attacker hosted sites.
2019-04-18T20:29:01.143
2024-11-21T04:42:23.933
Modified
CVSSv3.1: 8.0 (HIGH)
AV:A/AC:M/Au:N/C:C/I:C/A:C
5.5
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | dell | supportassist | < 3.2.0.90 | Yes |