// Security NEWS // A Critical Flaw in a Software Supporting Tens of Millions of PCs

A vulnerability in a PC-Doctor product allows you to take control of a machine. This software is distributed on Dell PCs under the name "SupportAssist". Fortunately, a patch is available.

Capture d’écran 2019-06-22 à 16.04.36.png

Source

If you have a Dell PC, update it immediately. A SafeBreach security researcher has found a critical flaw in the Dell SupportAssist support software that allows malware to take full control of the machine.

Indeed, one of the software components of this product does not securely load DLLs, does not specify a limit on the loading path and does not verify any signatures. An attacker can therefore quite easily introduce a poxed DLL and have it executed with system privileges.

Dell has already published a patch that needs to be installed. This flaw concerns both consumer and professional PCs. However, the American manufacturer is not the only one affected by this case.

Dell SupportAssist is actually a repackaging of the PC-Doctor solution. Those who use PC-Doctor Toolbox for Windows are therefore also concerned by this problem. According to PC-Doctor, this represents more than 100 million PCs worldwide.

Other vulnerable OEM solutions are in circulation, such as Corsair One Diagnostics, Corsair Diagnostics, Staples EasyTech Diagnostics, Tobii ISeries Diagnostic Tool and Tobii Dynavox Diagnostic Tool.

Credit: Dell would like to thank Peleg Hadar for reporting this vulnerability.

Severity Rating: For an explanation of Severity Ratings, refer to Dell’s Vulnerability Disclosure Policy. Dell EMC recommends all customers take into account both the base score and any relevant temporal and environmental scores which may impact the potential severity associated with particular security vulnerability.

Sources : SafeBreach and Dell

Stay Informed, Stay Safe

DQmdpsoEfLe5nRg4Q1oKWHNjLdMnAucCYfRou1yF5Yiwrzs.png

DQmNuF3L71zzxAyJB7Lk37yBqjBRo2uafTAudFDLzsoRV5L.gif

H2
H3
H4
Upload from PC
Video gallery
3 columns
2 columns
1 column
1 Comment