Uncontrolled Search Path Vulnerability in Dell SupportAssist
CVE-2020-5316

7.8HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
22 July 2021

Summary

Dell SupportAssist for Business and Home PCs contains a vulnerability that allows a locally authenticated low-privileged user to exploit an uncontrolled search path. This flaw enables an attacker to load arbitrary DLLs through SupportAssist binaries, potentially leading to the execution of privileged code on the affected system.

Affected Version(s)

Dell SupportAssist Client < unspecified

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.