DLL Injection Vulnerability in Dell SupportAssist Client for Consumer and Business PCs
CVE-2021-21518

7.8HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
12 March 2021

Summary

The Dell SupportAssist Client for Consumer and Business PCs has a security flaw due to a DLL injection vulnerability linked to the Costura Fody plugin. This flaw allows local users with minimal privileges to execute arbitrary code on the system with elevated privileges. The exploitation of this vulnerability can lead to significant security risks, enabling unauthorized access and control over the affected system. Dell has released a security update to address this issue.

Affected Version(s)

Dell SupportAssist Client < unspecified

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.