• Skip to main content
  • Skip to header right navigation
  • Skip to site footer
iGuRu

iGuRu

Real-time Technology News. Opinions & Tweaks

  • / news
  • / infosec
  • / tools
  • / tweaks
  • / dummies
  • / opinions
  • / support
home / News / Dell: Update your computers directly

Dell: Update your computers directly

02/05/2019 10:00 by giorgos

Dell released a security update to fix a vulnerability of its support software (SupportAssist Client). SupportAssist allows users from the same Network Access layer that have not been identified to remotely run malware executable on vulnerable computers.

dell logo - Dell: update your computers immediately

According to the company's website, SupportAssist software is "pre-installed on most of Dell's new devices running the Windows operating system" and "actively monitors the health of both the hardware and the system software." When it finds a problem, it sends it to Dell to start troubleshooting. ”

Most new Dell computers are exposed to Remote Code Execution (RCE) attacks.

The defect of the software has been reported as CVE-2019-3719 (CVSSv3) that reaches 8.0 from the National Vulnerability Database (or NVD)).

Dell updated SupportAssist software at the end of April of 2019 after an initial report received from a 17 security researcher (Bill Demirkapi) on 10 October 2018.

Dell advises all its clients to update the SupportAssist Client as soon as possible by indicating that all versions prior to 3.2.0.90 are vulnerable to remote code execution attacks.

Dell reportedly also repaired an improper origin validation flaw in the SupportAssist Client software reported by John C. Hennessy-ReCar, which has been reported as CVE-2019-3718 with a high-grade 3.0 rating (CVSS v8,8).

Security researcher Bill Demirkapi has discovered that RCE vulnerability can be exploited by attackers using ARP and DNS violations such as describes in detail on proof-of-concept which he published.

Watch the video demo on YouTube that shows its PoC

_________________

  • Secret Crush: New Feature on Facebook Dating
  • Windows 10: Free upgrade works yet
  • MIT: researcher solves a puzzle after 20 years
  • Windows 10 1903: Termination of passwords
  • Exercise in a Box by GCHQ: Try out the strengths of your business for free
Dell: Update your computers directly was last modified: May 2, 2019, 10: 00 am by giorgos

Subscribe to our newsletter

no spam

spread the news

  • Facebook
  • Twitter
  • Reddit
  • Printing
  • Email

Read them Technology News from all over the world, with the validity of iGuRu.gr

Follow us on Google News


Competition: NewsDay: 2018, dell, https, I'm sure, origin, SupportAssist, youtube

You May Also Like

Troubleshoot oobekeyboard and BIOS problems
YouTube prankster killed while recording video
Capture HTTPS / FTP packages with ARP Spoofing and MITM

About Us giorgos

George still wonders what he's doing here ...

Previous Post: « Red Hat: throws Shadowman and changes logo
Next Post: KeePass 2.42 New update »

Reader Interactions

Comment Policy:

IGuRu.gr does not publish the comments immediately. Malicious comments, comments that include ads, or comments that are offensive are deleted without notice. We do not adopt the opinions expressed by our readers.
Your comments will be displayed after approval by the administrators


Leave your comment
Ακύρωση απάντησης

Your email address is not published. Τα υποχρεωτικά πεδία σημειώνονται με *

 

 © 2021 · iGuRu.gr · ☢ · Keep It Simple Stupid Genesis theme

about  ·   get in touch  ·  rss  ·  sitemap  ·  cough

loadingCancel
Could not post post - check your email address!
Email verification failed, please try again
Your blog can not post posts via email.