• Cimpanu: An older (pre-April 23) version of Dell SupportAssist is vulnerable to a remote attack

    Home » Forums » Newsletter and Homepage topics » Cimpanu: An older (pre-April 23) version of Dell SupportAssist is vulnerable to a remote attack

    • This topic has 6 replies, 6 voices, and was last updated 6 years ago by anonymous.
    Author
    Topic
    #1186232

    Let’s hear it for the bloatware. From Catalin Cimpanu at ZDNet: A vulnerability in the Dell SupportAssist utility exposes Dell laptops and personal co
    [See the full post at: Cimpanu: An older (pre-April 23) version of Dell SupportAssist is vulnerable to a remote attack]

    7 users thanked author for this post.
    Viewing 3 reply threads
    Author
    Replies
    • #1186794

      I wonder how long until somebody figures out how to inject malware via Candy Crush?

      Don’t give them ideas, please!

      César

      • #1192947

        Candy Crush isn’t malware? It seems to be when running on Android!

        Win7 Pro SP1 64-bit, Dell Latitude E6330 ("The Tank"), Intel CORE i5 "Ivy Bridge", 12GB RAM, Group "0Patch", Multiple Air-Gapped backup drives in different locations. Linux Mint Newbie
        --
        "The more kinks you put in the plumbing, the easier it is to stop up the pipes." -Scotty

        1 user thanked author for this post.
    • #1188535

      The attacker needs to be on the victim’s network … to achieve remote code execution,” then it only needs ARP spoofing and DNS spoofing and a malicious web page somewhere to tempt the victim (who probably needs to be an administrator too). It’s not the simplest of attack scenarios.

      3 users thanked author for this post.
    • #1195600

      Doesn’t SupportAssist have an auto-update-mechanism for itself? I thought it did?

      1 user thanked author for this post.
      b
      • #1197378

        I have a Dell Inspiron laptop with Support Assist and it automatically updated on April 23 to version 3.2.1.94

        2 users thanked author for this post.
    • #1206026

      Mine didn’t auto update and when I did get it to update, it removed it from my start menu so that I couldn’t even open it. Since I have no warranty left and will not need it, I uninstalled it. That security hole is now plugged.

    Viewing 3 reply threads
    Reply To: Cimpanu: An older (pre-April 23) version of Dell SupportAssist is vulnerable to a remote attack

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: