Untrusted Search Path Vulnerability in Dell SupportAssist Client
CVE-2021-36297

7.8HIGH

Key Information:

Vendor

Dell

Vendor
CVE Published:
28 September 2021

What is CVE-2021-36297?

The SupportAssist Client versions 3.8 and 3.9 from Dell are susceptible to an untrusted search path vulnerability. This issue permits attackers to exploit the system by loading arbitrary .dll files through a process known as .dll planting or hijacking. This tactic requires a separate administrative action, which is not part of the standard installation executed by the SOSInstallerTool.exe. The flaw poses significant security risks, making it essential for users to apply available updates and mitigate potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SupportAssist Client Consumer 3.8, 3.9

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.