Privilege Escalation Vulnerability in Dell SupportAssist Software

CVE-2024-52535

7.1HIGH

Key Information

Vendor
Dell
Status
Supportassist For Home Pcs
Supportassist For Business Pcs
Vendor
CVE Published:
25 December 2024

Summary

Dell SupportAssist for Home PCs and Business PCs contains a vulnerability related to symbolic link attacks in the software's remediation component. This issue allows low-privileged, authenticated users to exploit the vulnerability, potentially escalating their privileges. Such exploitation may result in unauthorized deletion of files and folders from affected systems, posing significant risks to data integrity. Users are urged to update to the latest versions to mitigate potential threats and enhance security.

Affected Version(s)

SupportAssist for Home PCs < 4.6.2

SupportAssist for Business PCs < 4.5.1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database

Credit

Dell would like to thank mdanilor for reporting this issue.
.