Privilege Escalation Vulnerability in Dell SupportAssist Software
CVE-2024-52535

8.8HIGH

Key Information:

Vendor
Dell
Vendor
CVE Published:
25 December 2024

Summary

Dell SupportAssist for Home PCs and Business PCs contains a vulnerability related to symbolic link attacks in the software's remediation component. This issue allows low-privileged, authenticated users to exploit the vulnerability, potentially escalating their privileges. Such exploitation may result in unauthorized deletion of files and folders from affected systems, posing significant risks to data integrity. Users are urged to update to the latest versions to mitigate potential threats and enhance security.

Affected Version(s)

SupportAssist for Business PCs < 4.5.1

SupportAssist for Home PCs < 4.6.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dell would like to thank mdanilor for reporting this issue.
.